← Back to CVE List
Vulnerability Intelligence Report

CVE-2025-31702

A vulnerability exists in certain Dahua embedded products. Third-party malicious attacker with obtained normal user credentials could exploit the vulnerability to access certain data which are restricted to admin privileges, such as system-sensitive files through specific HTTP request. This may cause tampering with admin password, leading to privilege escalation. Systems with only admin account are not affected.

No Active Exploit Signals
CVSS Base Score
6.8
MEDIUM
Exploitability:1.7
Impact Score:5.2
EPSS Probability:0.27%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-732 ↗CWE-732 Incorrect Permission Assignment for Critical Resource

Affected Products & Versions

Vendor Product Affected Versions
Dahua IPC Affected products include certain models from the IPC-1XXX, IPC-2XXX, IPC-WX, and IPC-ECXX series, and limited to versions which build time prior to 1st July 2025 (not including 1st July 2025). (affected)
Dahua SD Affected products include certain models from the SD3A, SD2A, SD3D, SDT2A, and SD2C series, and limited to versions which build time prior to 1st July 2025 (not including 1st July 2025). (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.275%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityDahua Technologies · Vendor · China
Reserved2025-04-01T05:57:11
Published2025-10-15T05:53:35
Last Updated2025-10-15T13:25:09

LINK COPIED TO CLIPBOARD