Loading vulnerability details…
CVSS v3.1
9.8
EPSS
99.56%
Published
Sep 15, 2021
Modified
Jan 13, 2026
CISA Known Exploited Vulnerability
Added: 2024-08-21 · Due: 2024-09-11
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Public PoC / Exploit (3)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses (CWE)
Affected Products (38)
References (7)