Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)298▼ 212 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.64% | — | Dahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 FirmwareDahuasecurity Dhi-dss4004-s2 FirmwareDahuasecurity DSS Express+1 | 27/12/2022 | 17/6/2026 | Some Dahua software products have a vulnerability of unauthenticated restart of remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could unauthenticated restart of remote DSS Server. | |
| Modificada | Baja (3.7) | 0.41% | — | Dahuasecurity DSS ExpressDahuasecurity DSS ProfessionalDahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 Firmware+1 | 27/12/2022 | 17/6/2026 | Some Dahua software products have a vulnerability of unauthenticated enable or disable SSHD service. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could enable or disable the SSHD service. | |
| Modificada | Alta (7.5) | 0.53% | — | Dahuasecurity DSS ExpressDahuasecurity DSS ProfessionalDahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 Firmware+1 | 27/12/2022 | 17/6/2026 | Some Dahua software products have a vulnerability of server-side request forgery (SSRF). An Attacker can access internal resources by concatenating links (URL) that conform to specific rules. | |
| Modificada | Baja (2.7) | 0.68% | — | Dahuasecurity DSS ExpressDahuasecurity DSS ProfessionalDahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 Firmware+1 | 27/12/2022 | 17/6/2026 | Some Dahua software products have a vulnerability of sensitive information leakage. After obtaining the permissions of administrators, by sending a specific crafted packet to the vulnerable interface, an attacker can obtain the debugging information. | |
| Modificada | Alta (7.2) | 0.70% | — | Dahuasecurity DSS ExpressDahuasecurity DSS ProfessionalDahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 Firmware+1 | 27/12/2022 | 17/6/2026 | Some Dahua software products have a vulnerability of unrestricted upload of file. After obtaining the permissions of administrators, by sending a specific crafted packet to the vulnerable interface, an attacker can upload arbitrary files. | |
| Modificada | Media (6.5) | 0.58% | — | Dahuasecurity DSS ExpressDahuasecurity DSS ProfessionalDahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 Firmware+1 | 27/12/2022 | 17/6/2026 | Some Dahua software products have a vulnerability of unrestricted download of file. After obtaining the permissions of ordinary users, by sending a specific crafted packet to the vulnerable interface, an attacker can download arbitrary files. | |
| Modificada | Alta (7.5) | 0.53% | — | Dahuasecurity DSS ExpressDahuasecurity DSS ProfessionalDahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 Firmware+1 | 27/12/2022 | 17/6/2026 | Some Dahua software products have a vulnerability of using of hard-coded cryptographic key. An attacker can obtain the AES crypto key by exploiting this vulnerability. | |
| Modificada | Media (5.3) | 0.68% | — | Dahuasecurity DSS ExpressDahuasecurity DSS ProfessionalDahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 Firmware+1 | 27/12/2022 | 17/6/2026 | Some Dahua software products have a vulnerability of unauthenticated request of AES crypto key. An attacker can obtain the AES crypto key by sending a specific crafted packet to the vulnerable interface. | |
| Modificada | Alta (7.5) | 0.57% | — | Dahuasecurity DSS ExpressDahuasecurity DSS ProfessionalDahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 Firmware+1 | 27/12/2022 | 17/6/2026 | Some Dahua software products have a vulnerability of unauthenticated request of MQTT credentials. An attacker can obtain encrypted MQTT credentials by sending a specific crafted packet to the vulnerable interface (the credentials cannot be directly exploited). | |
| Modificada | Alta (7.4) | 0.98% | — | Dahuasecurity Ipc-hdbw2431e-s-s2 FirmwareDahuasecurity Ipc-hdbw2831e-s-s2 FirmwareDahuasecurity Ipc-hdbw2230e-s-s2 FirmwareDahuasecurity Ipc-hdbw2831r-zs-s2 Firmware+36 | 28/6/2022 | 17/6/2026 | When an attacker uses a man-in-the-middle attack to sniff the request packets with success logging in through ONVIF, he can log in to the device by replaying the user's login packet. | |
| Modificada | Media (4.7) | 0.71% | — | Dahuasecurity Ipc-hdbw2431e-s-s2 FirmwareDahuasecurity Ipc-hdbw2831e-s-s2 FirmwareDahuasecurity Ipc-hdbw2230e-s-s2 FirmwareDahuasecurity Ipc-hdbw2831r-zs-s2 Firmware+36 | 28/6/2022 | 17/6/2026 | If the user enables the https function on the device, an attacker can modify the user’s request data packet through a man-in-the-middle attack ,Injection of a malicious URL in the Host: header of the HTTP Request results in a 302 redirect to an attacker-controlled page. | |
| Modificada | Media (5.9) | 0.76% | — | Dahuasecurity Ipc-hdbw2431e-s-s2 FirmwareDahuasecurity Ipc-hdbw2831e-s-s2 FirmwareDahuasecurity Ipc-hdbw2230e-s-s2 FirmwareDahuasecurity Ipc-hdbw2831r-zs-s2 Firmware+36 | 28/6/2022 | 17/6/2026 | When an attacker uses a man-in-the-middle attack to sniff the request packets with success logging in, the attacker could log in to the device by replaying the user's login packet. | |
| Modificada | Alta (7.4) | 0.85% | — | Dahuasecurity Ipc-hdbw2431e-s-s2 FirmwareDahuasecurity Ipc-hdbw2831e-s-s2 FirmwareDahuasecurity Ipc-hdbw2230e-s-s2 FirmwareDahuasecurity Ipc-hdbw2831r-zs-s2 Firmware+36 | 28/6/2022 | 17/6/2026 | When an attacker obtaining the administrative account and password, or through a man-in-the-middle attack, the attacker could send a specified crafted packet to the vulnerable interface then lead the device to crash. | |
| Modificada | Crítica (9.8) | 1.3% | — | Dahuasecurity Ipc-hx1xxx FirmwareDahuasecurity Ipc-hx2xxx FirmwareDahuasecurity Ipc-hx3xxx FirmwareDahuasecurity Ipc-hx5(4)(3)xxx Firmware+24 | 13/1/2022 | 17/6/2026 | Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerability through specific deployments to reset device passwords. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Dahuasecurity Ipc-hum7xxx FirmwareDahuasecurity Ipc-hx3xxx FirmwareDahuasecurity Ipc-hx5xxx FirmwareDahuasecurity Nvr-1xxx Firmware+14 | 15/9/2021 | 17/6/2026 | The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Dahuasecurity Ipc-hum7xxx FirmwareDahuasecurity Ipc-hx3xxx FirmwareDahuasecurity Ipc-hx5xxx FirmwareDahuasecurity Sd1a1 Firmware+15 | 15/9/2021 | 17/6/2026 | The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets. | |
| Modificada | Crítica (9.8) | 1.5% | — | Dahuasecurity Sd6al FirmwareDahuasecurity Sd5a FirmwareDahuasecurity Sd1a FirmwareDahuasecurity Ptz1a Firmware+16 | 13/5/2020 | 17/6/2026 | Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user access, an attacker can use the predicted Session ID to construct a data packet to attack the device. | |
| Modificada | Media (5.5) | 0.34% | — | Dahuasecurity WEB P2P | 13/5/2020 | 17/6/2026 | Attackers can obtain Cloud Key information from the Dahua Web P2P control in specific ways. Cloud Key is used to authenticate the connection between the client tool and the platform. An attacker may use the leaked Cloud Key to impersonate the client to connect to the platform, resulting in additional consumption of… | |
| Modificada | Alta (8.1) | 0.86% | — | Dahuasecurity Sd6al FirmwareDahuasecurity Sd5a FirmwareDahuasecurity Sd1a FirmwareDahuasecurity Ptz1a Firmware+16 | 13/5/2020 | 17/6/2026 | Dahua devices with Build time before December 2019 use strong security login mode by default, but in order to be compatible with the normal login of early devices, some devices retain the weak security login mode that users can control. If the user uses a weak security login method, an attacker can monitor the device… | |
| Modificada | Media (4.9) | 1.0% | — | Dahuasecurity Sd6al FirmwareDahuasecurity Sd5a FirmwareDahuasecurity Sd1a FirmwareDahuasecurity Ptz1a Firmware+15 | 9/4/2020 | 17/6/2026 | Some products of Dahua have Denial of Service vulnerabilities. After the successful login of the legal account, the attacker sends a specific log query command, which may cause the device to go down. | |
| Modificada | Alta (7.2) | 1.5% | — | Dahuasecurity Sd6al FirmwareDahuasecurity Sd5a FirmwareDahuasecurity Sd1a FirmwareDahuasecurity Ptz1a Firmware+15 | 9/4/2020 | 17/6/2026 | Some Dahua products have buffer overflow vulnerabilities. After the successful login of the legal account, the attacker sends a specific DDNS test command, which may cause the device to go down. | |
| Modificada | Media (5.3) | 1.4% | — | Dahuasecurity Ipc-hdw1x2x FirmwareDahuasecurity Ipc-hfw1x2x FirmwareDahuasecurity Ipc-hdw2x2x FirmwareDahuasecurity Ipc-hfw2x2x Firmware+5 | 18/9/2019 | 17/6/2026 | Some Dahua products have information leakage issues. Attackers can obtain the IP address and device model information of the device by constructing malicious data packets. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for… | |
| Modificada | Alta (8.8) | 0.86% | — | Dahuasecurity Ipc-hdw1x2x FirmwareDahuasecurity Ipc-hfw1x2x FirmwareDahuasecurity Ipc-hdw2x2x FirmwareDahuasecurity Ipc-hfw2x2x Firmware+5 | 18/9/2019 | 17/6/2026 | Some of Dahua's Debug functions do not have permission separation. Low-privileged users can use the Debug function after logging in. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August… | |
| Modificada | Alta (7.5) | 1.0% | — | Dahuasecurity Ipc-hdw1x2x FirmwareDahuasecurity Ipc-hfw1x2x FirmwareDahuasecurity Ipc-hdw2x2x FirmwareDahuasecurity Ipc-hfw2x2x Firmware+5 | 18/9/2019 | 17/6/2026 | Some Dahua products have the problem of denial of service during the login process. An attacker can cause a device crashed by constructing a malicious packet. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build… | |
| Modificada | Crítica (9.8) | 1.1% | — | Dahuasecurity Ipc-hdw1x2x FirmwareDahuasecurity Ipc-hfw1x2x FirmwareDahuasecurity Ipc-hdw2x2x FirmwareDahuasecurity Ipc-hfw2x2x Firmware+5 | 18/9/2019 | 17/6/2026 | The specific fields of CGI interface of some Dahua products are not strictly verified, an attacker can cause a buffer overflow by constructing malicious packets. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which… |