Vulnerability Intelligence Report
CVE-2025-31702
A vulnerability exists in certain Dahua embedded products. Third-party malicious attacker with obtained normal user credentials could exploit the vulnerability to access certain data which are restricted to admin privileges, such as system-sensitive files through specific HTTP request. This may cause tampering with admin password, leading to privilege escalation. Systems with only admin account are not affected.
No Active Exploit Signals
CVSS Base Score
6.8
MEDIUM
Exploitability:1.7
Impact Score:5.2
EPSS Probability:0.27%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-732 ↗CWE-732 Incorrect Permission Assignment for Critical Resource
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Dahua | IPC | Affected products include certain models from the IPC-1XXX, IPC-2XXX, IPC-WX, and IPC-ECXX series, and limited to versions which build time prior to 1st July 2025 (not including 1st July 2025). (affected) |
| Dahua | SD | Affected products include certain models from the SD3A, SD2A, SD3D, SDT2A, and SD2C series, and limited to versions which build time prior to 1st July 2025 (not including 1st July 2025). (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.275%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Dahua Technologies · Vendor · China |
| Reserved | 2025-04-01T05:57:11 |
| Published | 2025-10-15T05:53:35 |
| Last Updated | 2025-10-15T13:25:09 |
Community Chatter & Buzz