Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-29115 — Dahua CVE-2026-29115 | Kitploit
Tools/GitHubGitHub/crimsonfiedofficial/cve-2026-29115
Embedded Systems SecurityIoT SecurityVulnerability AnalysisExploitationHardware & IoT Security
GitHubcrimsonfiedofficial/cve-2026-29115

CVE-2026-29115

Dahua CVE-2026-29115

View Repository
1152 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-29115 — Dahua Authenticated Remote Denial of Service

CVSS 4.0 Remotely Exploitable Authentication

Advisory type: Vendor-coordinated security disclosure
CVE ID: CVE-2026-29115
Vendor: Dahua Technology
Published: 2026-06-10T06:08:21 UTC
Last Modified: 2026-06-10T06:08:21 UTC
Source: Dahua Product Security Incident (PSI) Trust Center


Table of Contents

  • Executive Summary
  • At a Glance
  • Relationship to CVE-2026-29116
  • Vulnerability Timeline
  • Description
  • Technical Analysis
  • Affected Products
  • CVSS Scoring
  • Vulnerability Scoring Details
  • CWE Classification
  • Attack Prerequisites
  • Exploitation Scenarios
  • Impact Assessment
  • Detection and Indicators of Compromise
  • Mitigation and Remediation
  • Workarounds
  • Vendor Response
  • References
  • Disclaimer
  • Document Revision History

Executive Summary

A medium-severity, authenticated remote denial-of-service vulnerability has been identified in select Dahua IPC (IP camera) and SD (speed dome / PTZ) products. An attacker who already possesses valid device credentials can send a specially crafted network packet to a vulnerable unit. Processing that packet triggers an unhandled exception (consistent with a reachable assertion or fatal error path), causing the device to reboot unexpectedly.

Unlike its sibling disclosure CVE-2026-29116, which requires no authentication, this flaw demands high privileges (PR:H) on the target device. That constraint reduces practical exploitability for opportunistic internet-wide attackers, but the risk remains material in environments where camera credentials are shared, default, leaked, or recoverable — a common condition in legacy CCTV deployments.

The vulnerability does not demonstrate direct confidentiality or integrity impact in the published CVSS vector. Availability impact is rated High, producing a CVSS 4.0 base score of 6.9 (MEDIUM).

Organizations operating affected Dahua IPC or SD hardware with firmware builds prior to March 26, 2026 should patch, rotate credentials, and restrict management-plane access.

Note on advisory labeling: Some indexes title this CVE "Dahua Buffer Overflow." The vendor description, CVSS metrics (VA:H only), and CWE-617 (Reachable Assertion) classification describe a crash/reboot denial-of-service after authenticated packet delivery — not a scored memory-corruption confidentiality/integrity breach. This document follows the vendor description and scoring data. Buffer handling may still be part of the underlying defect, but the published impact is availability-only.


At a Glance

FieldValue
CVE IDCVE-2026-29115
VendorDahua Technology
Vulnerability TypeDenial of Service (unexpected reboot)
Attack VectorNetwork
Authentication RequiredYes (high privileges)
User Interaction RequiredNo
Privileges RequiredHigh
CVSS Version4.0
CVSS Base Score6.9 — MEDIUM
CVSS VectorCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CWECWE-617 (Reachable Assertion)
Remotely ExploitableYes
Published Date2026-06-10
Fix AvailabilityFirmware builds from March 26, 2026 onward (per vendor guidance)

Relationship to CVE-2026-29116

Both CVEs were published on 2026-06-10 from the same Dahua PSI disclosure batch. They share structural similarities but differ in scope and attacker model.

AttributeCVE-2026-29115 (this advisory)CVE-2026-29116
CVSS 4.0 Score6.9 — MEDIUM8.7 — HIGH
Privileges RequiredHigh (PR:H)None (PR:N)
Affected FamiliesIPC, SDIPC, SD, NVR, XVR, EVS, VTO, VTH, ASI, TPC
Published (UTC)2026-06-10T06:08:212026-06-10T06:16:34
Observed OutcomeUnexpected reboot (DoS)Unexpected reboot (DoS)
CWECWE-617CWE-617
Index TitleBuffer OverflowCross-Site Scripting (mislabeled)

Defender takeaway: Patch both issues on overlapping IPC/SD estates. Prioritize 29116 for internet-exposed devices (unauthenticated). Prioritize 29115 where operator or integrator credentials are widely known, stored in VMS databases, or embedded in mobile apps.


Vulnerability Timeline

DateEvent
≤ 2026-03-26Vulnerable IPC/SD firmware builds in active distribution
2026-03-26Vendor fix cutoff — builds produced on or after this date are outside the affected range (per advisory)
2026-06-10T06:08:21 UTCCVE-2026-29115 published
2026-06-10T06:08:21 UTCNVD record last modified
2026-06-10T06:16:34 UTCRelated CVE-2026-29116 published (unauthenticated variant)
OngoingOperators should inventory IPC/SD fleets, patch, and harden credentials

Description

Dahua has reported a security vulnerability affecting certain models within its IPC and SD product lines. The flaw exists in network-accessible software that accepts authenticated sessions and processes attacker-influenced protocol data without sufficient validation or safe failure handling.

Observed behavior:

  1. An authenticated remote attacker with high privileges on the device transmits a specially crafted packet over the network.
  2. The device's handler processes the packet and enters an exceptional code path — for example, a failed assertion, unhandled fault, or unrecoverable internal error consistent with CWE-617 (Reachable Assertion).
  3. The exception causes the system to reboot unexpectedly.
  4. The camera or speed dome remains unavailable until the reboot completes. Repeated exploitation can cause sustained denial of service.

What this vulnerability is not (per CVSS metrics):

  • It does not require victim user interaction such as opening a malicious link (UI:N).
  • It does not demonstrate direct confidentiality impact (VC:N).
  • It does not demonstrate direct integrity impact (VI:N).
  • It does not show subsequent-system impact (SC:N, SI:N, SA:N).

What distinguishes it from unauthenticated variants:

  • The attacker must already hold credentials sufficient to satisfy the device's high privilege threshold (PR:H). In practice this often maps to administrative or equivalent device-level accounts rather than read-only monitoring users — exact role mapping is product-specific and should be confirmed against vendor documentation.

Technical Analysis

Root Cause (Inferred)

Public vendor text does not disclose the vulnerable function, service name, or exact buffer dimensions. Based on the published CWE, title, and behavior, plausible root-cause categories include:

Download Tool