Denial of Service Vulnerability in Dahua Security Products
CVE-2026-29115
Key Information:
Badges
What is CVE-2026-29115?
A vulnerability identified in various Dahua security products enables an authenticated remote attacker to transmit a specially crafted packet. This can trigger an exception within the system, leading to an unexpected reboot of the device. Consequently, this vulnerability poses a risk of denial of service, impacting the availability and functionality of the affected products.
Affected Version(s)
IPC/SD Affected products are limited to certain models of IPC and SD devices with a build time before March 26, 2026.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
