Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/crimsonfiedofficial/cve-2026-29114
IoT SecurityVulnerability AnalysisCryptographyPenetration TestingHardware SecurityLearning & Education
GitHubcrimsonfiedofficial/cve-2026-29114

CVE-2026-29114

Dahua CVE-2026-29114

View Repository
1172 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-29114 — Dahua Exposed Device CA Root Certificate

CVSS 4.0 Remotely Exploitable Authentication

Advisory type: Vendor-coordinated security disclosure
CVE ID: CVE-2026-29114
Vendor: Dahua Technology
Published: 2026-06-10T05:44:50 UTC
Last Modified: 2026-06-10T05:44:50 UTC
Source: Dahua Product Security Incident (PSI) Trust Center


Table of Contents

  • Executive Summary
  • At a Glance
  • Relationship to Related CVEs
  • Vulnerability Timeline
  • Description
  • Technical Analysis
  • Affected Products
  • CVSS Scoring
  • Vulnerability Scoring Details
  • CWE Classification
  • Attack Prerequisites
  • Exploitation Scenarios
  • Impact Assessment
  • Detection and Indicators of Compromise
  • Mitigation and Remediation
  • Workarounds
  • Vendor Response
  • References
  • Disclaimer
  • Document Revision History

Executive Summary

A low-severity certificate-trust vulnerability has been identified in select Dahua IPC (IP camera) models. Under certain deployment conditions, a remote attacker can obtain the device's internal CA root certificate — material that should remain private to the certificate authority hierarchy.

If that root CA (or an intermediate derived from it) has been installed and trusted on client workstations, browsers, or middleware, an attacker who possesses the private key material can mint fraudulent X.509 certificates that validating clients will accept as legitimate. That enables person-in-the-middle (MITM) attacks against HTTPS or TLS-protected sessions that chain to the compromised trust anchor, undermining the confidentiality and integrity of affected client connections.

The published CVSS 4.0 base score is 2.3 (LOW). The relatively low score reflects deployment preconditions (AT:P — attack requirements present) and passive user interaction (UI:P) needed for practical impact, plus Low (not High) direct confidentiality and integrity ratings on the vulnerable device itself. Availability is not impacted (VA:N).

Organizations running affected IPC firmware builds before April 15, 2026 should verify whether device-issued CAs were ever distributed to endpoints, remove untrusted roots from client trust stores, rotate TLS configurations, and upgrade firmware.

Note on advisory labeling: Some indexes title this CVE "Dahua Data Breach." The vendor description concerns exposure of a device CA root certificate and downstream PKI trust abuse — not bulk exfiltration of recorded video or customer databases. This document follows the vendor description and CVSS scoring data.


At a Glance

FieldValue
CVE IDCVE-2026-29114
VendorDahua Technology
Vulnerability TypeSensitive certificate material exposure / trust-chain abuse
Attack VectorNetwork
Authentication RequiredNo
User Interaction RequiredPassive (UI:P)
Attack RequirementsPresent (AT:P)
Privileges RequiredNone
CVSS Version4.0
CVSS Base Score2.3 — LOW
CVSS VectorCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-538 (Insertion of Sensitive Information into Externally-Accessible File or Directory)
Remotely ExploitableYes
Published Date2026-06-10
Fix AvailabilityFirmware builds from April 15, 2026 onward (per vendor guidance)

Relationship to Related CVEs

CVE-2026-29114 was published on 2026-06-10 alongside other Dahua PSI disclosures from the same batch. The issues are distinct in mechanism and impact profile.

AttributeCVE-2026-29114 (this advisory)CVE-2026-29115CVE-2026-29116
CVSS 4.0 Score2.3 — LOW6.9 — MEDIUM8.7 — HIGH
Primary ImpactConfidentiality + Integrity (Low)Availability (High)Availability (High)
AuthenticationNot requiredHigh privileges requiredNot required
Affected ProductsIPC onlyIPC, SDIPC, SD, NVR, XVR, EVS, VTO, VTH, ASI, TPC
Fix Build CutoffBefore 2026-04-15Before 2026-03-26Before 2026-03-26
CWECWE-538CWE-617CWE-617
Published (UTC)2026-06-10T05:44:502026-06-10T06:08:212026-06-10T06:16:34

Defender takeaway: This CVE is not a camera reboot flaw. It is a PKI hygiene and trust-store problem. Patching matters, but removing improperly trusted device CAs from client machines is often the decisive remediation step.


Vulnerability Timeline

DateEvent
≤ 2026-04-15Vulnerable IPC firmware builds in active distribution
2026-04-15Vendor fix cutoff — builds produced on or after this date are outside the affected range (per advisory)
2026-06-10T05:44:50 UTCCVE-2026-29114 published
2026-06-10T05:44:50 UTCNVD record last modified
2026-06-10Related CVE-2026-29115 and CVE-2026-29116 published later same day
OngoingOperators should audit trust stores and IPC firmware build dates

Description

Dahua has reported a vulnerability in some IPC models whereby sensitive certificate authority (CA) material associated with the device can be obtained by a remote party. The vendor states that an attacker may obtain the device's CA root certificate.

Trust-Chain Consequences

X.509 PKI security depends on private keys staying secret and trust anchors being deliberately chosen. If:

  1. The device's root CA certificate and corresponding private key (or recoverable signing material) are exposed, and
  2. That CA has been installed as a trusted root (or trusted intermediate) on client systems — for example operator PCs, VMS middleware, or corporate browser trust stores,

then an attacker can:

  • Issue arbitrary fraudulent certificates appearing valid under that CA
  • Intercept or modify TLS-protected traffic between users and services that trust the compromised anchor
  • Undermine certificate validation without triggering standard public-CA warnings

CVSS-Scoped Impact

Per the published vector:

  • Confidentiality (VC:L) — Low direct impact on the vulnerable IPC
  • Integrity (VI:L) — Low direct impact on the vulnerable IPC
  • Availability (VA:N) — No availability impact on the device itself
  • Subsequent impacts — Not scored (SC:N, SI:N, SA:N)

Practical harm often manifests on client systems that trust the exposed CA, which is why attack requirements and user interaction metrics are elevated in the scoring model.


Technical Analysis

What Is a Device-Embedded CA?

Many embedded devices ship with factory or firmware-bundled PKI to support:

Download Tool