Skip to finding
important · Firmware

A newly shipped working exploit turns Dahua’s unauthenticated ONVIF overflow into a root shell.

Affects

Dahua IPC and SD-series embedded surveillance cameras and recorders running affected firmware builds.

The attacker needs reachability to the camera’s ONVIF HTTP handler, normally from the LAN but sometimes through port forwarding or UPnP.

Detail and 3 sources

A crafted Host header overwrites control data, and a ROP chain invokes attacker-supplied commands.

A patch exists, but the exact target build used by the new exploit is not established in the material held here.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, October 3, 2026