important · Firmware
A newly shipped working exploit turns Dahua’s unauthenticated ONVIF overflow into a root shell.
Affects
Dahua IPC and SD-series embedded surveillance cameras and recorders running affected firmware builds.
The attacker needs reachability to the camera’s ONVIF HTTP handler, normally from the LAN but sometimes through port forwarding or UPnP.
Detail and 3 sources
A crafted Host header overwrites control data, and a ROP chain invokes attacker-supplied commands.
A patch exists, but the exact target build used by the new exploit is not established in the material held here.
Sources
ResearchNew exploits and detections for Citrix NetScaler x3, Cisco SD-WAN, Oracle PeopleSoft, Zammad, Roundcube Webmail, Microsoft SharePoint, Rejetto HFS, the Linux kernel, and many, many more. - Initial AccessResearchVulnerabilities Identified in Dahua Hero C1 Smart CamerasCVEhttps://cve.org/CVERecord?id=CVE-2025-31700