
Technical advisory and proof-of-concept for CVE-2024-13985, a critical unauthenticated remote code execution vulnerability in Dahua EIMS via command injection in the capture_handle.action endpoint.
capture_handle.action Remote Code ExecutionAdvisory type: Vendor-coordinated security disclosure · Active exploitation reported
CVE ID: CVE-2024-13985
CNVD ID: CNVD-2024-17054
Vendor: Zhejiang Dahua Technology Co., Ltd.
Product: EIMS (Enterprise Information Management System)
Published: 2025-08-27T21:23:37 UTC
Last Modified: 2026-05-15T11:14:33 UTC
Source: Dahua Support Bulletin
A critical, unauthenticated remote code execution vulnerability exists in Dahua EIMS (Enterprise Information Management System) versions prior to 2240008. The flaw is a command injection in the HTTP endpoint capture_handle.action, where the captureCommand parameter is passed to an underlying OS command executor without authentication, sanitization, or adequate input validation.
Any remote attacker who can reach the EIMS web interface can send crafted HTTP requests that inject arbitrary operating-system commands. Those commands execute in the server context, enabling full system compromise — data theft, persistence, lateral movement, ransomware deployment, and disruption of dependent physical-security workflows.
The vulnerability receives the maximum CVSS 4.0 base score of 10.0 (CRITICAL) with High impact across confidentiality, integrity, and availability on both the vulnerable system and subsequent systems (VC:H/VI:H/VA:H/SC:H/SI:H/SA:H). Exploitation evidence has been observed in the wild.
EIMS is an enterprise back-end platform, not a field IPC camera. Compromise typically affects central management, access control integrations, and organizational data rather than a single sensor. Treat internet-exposed or VLAN-reachable EIMS instances as emergency patch priority.
| Field | Value |
|---|---|
| CVE ID | CVE-2024-13985 |
| CNVD ID | CNVD-2024-17054 |
| Vendor | Zhejiang Dahua Technology Co., Ltd. |
| Product | EIMS (Enterprise Information Management System) |
| Vulnerability Type | OS Command Injection → Remote Code Execution |
| Vulnerable Endpoint | capture_handle.action |
| Vulnerable Parameter | captureCommand |
| Attack Vector | Network |
| Authentication Required | No |
| User Interaction Required | No |
| Privileges Required | None |
| CVSS Version | 4.0 |
| CVSS Base Score | 10.0 — CRITICAL |
| CVSS Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
| CWE | CWE-78 (OS Command Injection) |
| Remotely Exploitable | Yes |
| Affected Versions | All versions < 2240008 |
| Fixed Version | 2240008 and later |
| Published Date | 2025-08-27 |
| Last Modified | 2026-05-15 |
| Exploitation in the Wild | Yes (reported) |
This repository also documents field-device advisories from Dahua's 2026 PSI batch. CVE-2024-13985 is a separate product line with a far higher severity profile.
| Attribute | CVE-2024-13985 (this advisory) | CVE-2026-29116 | CVE-2026-29115 | CVE-2026-29114 |
|---|---|---|---|---|
| Product | EIMS server | IPC/NVR/etc. | IPC/SD | IPC |
| CVSS 4.0 | 10.0 CRITICAL | 8.7 HIGH | 6.9 MEDIUM | 2.3 LOW |
| Auth | None | None | High privileges | None |
| Primary Impact | Full RCE | DoS (reboot) | DoS (reboot) | CA cert exposure |
| CWE | CWE-78 | CWE-617 | CWE-617 | CWE-538 |
| In-the-wild | Yes | Not stated | Not stated | Not stated |
Defender takeaway: Patching cameras does not remediate EIMS. Inventory application servers running Dahua enterprise software independently.
| Date | Event |
|---|---|
| ≤ 2024 | Vulnerable EIMS releases deployed in enterprise environments |
| 2024 | Vulnerability discovered / reported (CVE year 2024) |
| 2024 | CNVD-2024-17054 assigned (China National Vulnerability Database) |
| 2025-08-27T21:23:37 UTC | CVE-2024-13985 published to NVD/CVE.org |
| 2025–2026 | Public scanners, PoC discussions, and nuclei templates circulate |
| Post-publication | Exploitation evidence observed in the wild |
| 2026-05-15T11:14:33 UTC | NVD record last modified |
| Ongoing | Internet-exposed EIMS instances remain high-value targets |
Dahua EIMS provides enterprise-level information management capabilities used in integrated security and building-management deployments. A network-facing servlet or action handler exposed at capture_handle.action accepts a parameter named captureCommand.
The application treats captureCommand as input to a host operating system command (directly or via a shell wrapper) without:
An unauthenticated attacker submits crafted HTTP requests containing command injection payloads in captureCommand. The server executes attacker-controlled OS commands with the privileges of the EIMS application process — typically a privileged service account on Windows or Linux hosts.
Successful exploitation leads to:
| Outcome | Detail |
|---|---|
| Remote Code Execution | Arbitrary binaries, scripts, or shell commands |
| Full system compromise | File read/write, user creation, service manipulation |
| Lateral movement | Pivot from EIMS host into AD, databases, camera VLANs |
| Data exfiltration | Access to EIMS-managed enterprise records |
| Service disruption | Stop EIMS, wipe data, deploy ransomware |
| Supply-chain positioning | Backdoor software update or device provisioning channels |