important · Firmware — RCE
A public demonstration turns Dahua’s ONVIF stack overflow into an unauthenticated root reverse shell.
Affects
Dahua IPC and SD-series embedded network and PTZ cameras.
The demonstration establishes execution control beyond the original advisory’s emphasis on disruption and exploit-protection assumptions.
Detail and 3 sources
Firmware updates are published for affected Dahua families.
Sources
ResearchNew exploits and detections for Citrix NetScaler x3, Cisco SD-WAN, Oracle PeopleSoft, Zammad, Roundcube Webmail, Microsoft SharePoint, Rejetto HFS, the Linux kernel, and many, many more. - Initial AccessResearchTT-CSIRT – 443.30.07.25 – Vulnerabilities found in some Dahua productsCVEhttps://cve.org/CVERecord?id=CVE-2025-31700