Privilege Escalation Vulnerability in Dahua Embedded Products
CVE-2025-31702

6.8MEDIUM

Key Information:

Vendor

Dahua

Status
Vendor
CVE Published:
15 October 2025

What is CVE-2025-31702?

A vulnerability in certain Dahua embedded products enables a malicious third-party attacker, armed with valid user credentials, to execute specific HTTP requests. This can lead to unauthorized access to sensitive data typically restricted to admin privileges, potentially allowing the attacker to tamper with the admin password and escalate their privileges. Notably, affected systems with only admin accounts are not susceptible to this flaw.

Affected Version(s)

IPC Affected products include certain models from the IPC-1XXX, IPC-2XXX, IPC-WX, and IPC-ECXX series, and limited to versions which build time prior to 1st July 2025 (not including 1st July 2025).

SD Affected products include certain models from the SD3A, SD2A, SD3D, SDT2A, and SD2C series, and limited to versions which build time prior to 1st July 2025 (not including 1st July 2025).

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-31702 : Privilege Escalation Vulnerability in Dahua Embedded Products