Privilege Escalation Vulnerability in Dahua Embedded Products
CVE-2025-31702
What is CVE-2025-31702?
A vulnerability in certain Dahua embedded products enables a malicious third-party attacker, armed with valid user credentials, to execute specific HTTP requests. This can lead to unauthorized access to sensitive data typically restricted to admin privileges, potentially allowing the attacker to tamper with the admin password and escalate their privileges. Notably, affected systems with only admin accounts are not susceptible to this flaw.
Affected Version(s)
IPC Affected products include certain models from the IPC-1XXX, IPC-2XXX, IPC-WX, and IPC-ECXX series, and limited to versions which build time prior to 1st July 2025 (not including 1st July 2025).
SD Affected products include certain models from the SD3A, SD2A, SD3D, SDT2A, and SD2C series, and limited to versions which build time prior to 1st July 2025 (not including 1st July 2025).