Vulnerability Intelligence Report
CVE-2026-29116
A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially crafted packet, triggering an exception that causes the system to reboot unexpectedly, resulting in a denial of service.
No Active Exploit Signals
CVSS Base Score
8.7
HIGH
EPSS Probability:0.40%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-617 ↗CWE-617
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Dahua | IPC/SD/NVR/XVR/EVS/VTO/VTH/ASI/TPC | Affected products are limited to certain models of IPC, SD, NVR, XVR, EVS, VTO, VTH, ASI, and TPC devices with versions built before March 26, 2026. (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.395%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Dahua Technologies · Vendor · China |
| Reserved | 2026-03-04T03:32:28 |
| Published | 2026-06-10T06:16:34 |
| Last Updated | 2026-06-10T14:50:16 |
Community Chatter & Buzz