Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-13985 — Technical advisory and proof-of-concept for CVE-2024-13985, a critical unauthenticated remote code execution vulnerability in Dahua EIMS via command injection in the capture_handle.action endpoint. | Kitploit
Tools/GitHubGitHub/crimsonfiedofficial/cve-2024-13985
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingCommand and ControlRed Teaming
GitHubcrimsonfiedofficial/cve-2024-13985

CVE-2024-13985

Technical advisory and proof-of-concept for CVE-2024-13985, a critical unauthenticated remote code execution vulnerability in Dahua EIMS via command injection in the capture_handle.action endpoint.

View Repository
1132 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-13985 — Dahua EIMS capture_handle.action Remote Code Execution

CVSS 4.0 Remotely Exploitable Authentication In the Wild

Advisory type: Vendor-coordinated security disclosure · Active exploitation reported
CVE ID: CVE-2024-13985
CNVD ID: CNVD-2024-17054
Vendor: Zhejiang Dahua Technology Co., Ltd.
Product: EIMS (Enterprise Information Management System)
Published: 2025-08-27T21:23:37 UTC
Last Modified: 2026-05-15T11:14:33 UTC
Source: Dahua Support Bulletin


Table of Contents

  • Executive Summary
  • At a Glance
  • Relationship to Other Dahua CVEs
  • Vulnerability Timeline
  • Description
  • Technical Analysis
  • Affected Products
  • CVSS Scoring
  • Vulnerability Scoring Details
  • CWE Classification
  • Attack Prerequisites
  • Exploitation Scenarios
  • Impact Assessment
  • Asset Discovery
  • Detection and Indicators of Compromise
  • Mitigation and Remediation
  • Workarounds
  • Vendor Response
  • References
  • Disclaimer
  • Document Revision History

Executive Summary

A critical, unauthenticated remote code execution vulnerability exists in Dahua EIMS (Enterprise Information Management System) versions prior to 2240008. The flaw is a command injection in the HTTP endpoint capture_handle.action, where the captureCommand parameter is passed to an underlying OS command executor without authentication, sanitization, or adequate input validation.

Any remote attacker who can reach the EIMS web interface can send crafted HTTP requests that inject arbitrary operating-system commands. Those commands execute in the server context, enabling full system compromise — data theft, persistence, lateral movement, ransomware deployment, and disruption of dependent physical-security workflows.

The vulnerability receives the maximum CVSS 4.0 base score of 10.0 (CRITICAL) with High impact across confidentiality, integrity, and availability on both the vulnerable system and subsequent systems (VC:H/VI:H/VA:H/SC:H/SI:H/SA:H). Exploitation evidence has been observed in the wild.

EIMS is an enterprise back-end platform, not a field IPC camera. Compromise typically affects central management, access control integrations, and organizational data rather than a single sensor. Treat internet-exposed or VLAN-reachable EIMS instances as emergency patch priority.


At a Glance

FieldValue
CVE IDCVE-2024-13985
CNVD IDCNVD-2024-17054
VendorZhejiang Dahua Technology Co., Ltd.
ProductEIMS (Enterprise Information Management System)
Vulnerability TypeOS Command Injection → Remote Code Execution
Vulnerable Endpointcapture_handle.action
Vulnerable ParametercaptureCommand
Attack VectorNetwork
Authentication RequiredNo
User Interaction RequiredNo
Privileges RequiredNone
CVSS Version4.0
CVSS Base Score10.0 — CRITICAL
CVSS VectorCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CWECWE-78 (OS Command Injection)
Remotely ExploitableYes
Affected VersionsAll versions < 2240008
Fixed Version2240008 and later
Published Date2025-08-27
Last Modified2026-05-15
Exploitation in the WildYes (reported)

Relationship to Other Dahua CVEs

This repository also documents field-device advisories from Dahua's 2026 PSI batch. CVE-2024-13985 is a separate product line with a far higher severity profile.

AttributeCVE-2024-13985 (this advisory)CVE-2026-29116CVE-2026-29115CVE-2026-29114
ProductEIMS serverIPC/NVR/etc.IPC/SDIPC
CVSS 4.010.0 CRITICAL8.7 HIGH6.9 MEDIUM2.3 LOW
AuthNoneNoneHigh privilegesNone
Primary ImpactFull RCEDoS (reboot)DoS (reboot)CA cert exposure
CWECWE-78CWE-617CWE-617CWE-538
In-the-wildYesNot statedNot statedNot stated

Defender takeaway: Patching cameras does not remediate EIMS. Inventory application servers running Dahua enterprise software independently.


Vulnerability Timeline

DateEvent
≤ 2024Vulnerable EIMS releases deployed in enterprise environments
2024Vulnerability discovered / reported (CVE year 2024)
2024CNVD-2024-17054 assigned (China National Vulnerability Database)
2025-08-27T21:23:37 UTCCVE-2024-13985 published to NVD/CVE.org
2025–2026Public scanners, PoC discussions, and nuclei templates circulate
Post-publicationExploitation evidence observed in the wild
2026-05-15T11:14:33 UTCNVD record last modified
OngoingInternet-exposed EIMS instances remain high-value targets

Description

Dahua EIMS provides enterprise-level information management capabilities used in integrated security and building-management deployments. A network-facing servlet or action handler exposed at capture_handle.action accepts a parameter named captureCommand.

Failure Mode

The application treats captureCommand as input to a host operating system command (directly or via a shell wrapper) without:

  • Requiring an authenticated session
  • Validating allowed character sets or command vocabulary
  • Escaping shell metacharacters
  • Using safe APIs (e.g., parameterized process invocation with fixed executable and argument array)

An unauthenticated attacker submits crafted HTTP requests containing command injection payloads in captureCommand. The server executes attacker-controlled OS commands with the privileges of the EIMS application process — typically a privileged service account on Windows or Linux hosts.

Consequences

Successful exploitation leads to:

OutcomeDetail
Remote Code ExecutionArbitrary binaries, scripts, or shell commands
Full system compromiseFile read/write, user creation, service manipulation
Lateral movementPivot from EIMS host into AD, databases, camera VLANs
Data exfiltrationAccess to EIMS-managed enterprise records
Service disruptionStop EIMS, wipe data, deploy ransomware
Supply-chain positioningBackdoor software update or device provisioning channels

Technical Analysis

Endpoint and Parameter

Download Tool