Information Disclosure Vulnerability in Dahua IPC Cameras
CVE-2024-13131
What is CVE-2024-13131?
A significant information disclosure vulnerability affects multiple Dahua IPC camera models, enabling attackers to remotely access sensitive information through the compromised web interface component. The flaw exists in the /web_caps/webCapsConfig file, which can be exploited without user interaction, exposing critical system data. Despite prior notifications to the vendor regarding this exploit, no public response has been provided, heightening the urgency for users to secure their devices against potential threats.
Affected Version(s)
IPC-HDW1200S 20241222
IPC-HFW1200S 20241222
IPC-HFW2300R-Z 20241222
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved