Authentication Bypass in Dahua IPC/VTH/VTO Devices

ISGroup Cybersecurity

A significant authentication bypass vulnerability has been identified and is currently being actively exploited in numerous Dahua devices. This flaw affects a wide range of IP devices manufactured by Dahua, more than two million of which are accessible via the internet. Attackers are able to bypass the device authentication process by crafting and sending malicious data packets, thereby gaining unauthorized access to a significant number of commonly used devices.

ProductDahua IP Cameras
Date2024-08-26 09:49:18

Technical Summary

The identity bypass vulnerability during authentication, detected in certain Dahua products during the login procedure, is currently being actively exploited. This flaw affects a wide range of Dahua devices, with over 2 million units accessible via the internet. Attackers bypass device identity authentication by crafting and sending malicious data packets, thus gaining unauthorized access to a significant number of commonly used devices.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert