
Dahua CVE-2026-29115
Advisory type: Vendor-coordinated security disclosure
CVE ID: CVE-2026-29115
Vendor: Dahua Technology
Published: 2026-06-10T06:08:21 UTC
Last Modified: 2026-06-10T06:08:21 UTC
Source: Dahua Product Security Incident (PSI) Trust Center
A medium-severity, authenticated remote denial-of-service vulnerability has been identified in select Dahua IPC (IP camera) and SD (speed dome / PTZ) products. An attacker who already possesses valid device credentials can send a specially crafted network packet to a vulnerable unit. Processing that packet triggers an unhandled exception (consistent with a reachable assertion or fatal error path), causing the device to reboot unexpectedly.
Unlike its sibling disclosure CVE-2026-29116, which requires no authentication, this flaw demands high privileges (PR:H) on the target device. That constraint reduces practical exploitability for opportunistic internet-wide attackers, but the risk remains material in environments where camera credentials are shared, default, leaked, or recoverable — a common condition in legacy CCTV deployments.
The vulnerability does not demonstrate direct confidentiality or integrity impact in the published CVSS vector. Availability impact is rated High, producing a CVSS 4.0 base score of 6.9 (MEDIUM).
Organizations operating affected Dahua IPC or SD hardware with firmware builds prior to March 26, 2026 should patch, rotate credentials, and restrict management-plane access.
Note on advisory labeling: Some indexes title this CVE "Dahua Buffer Overflow." The vendor description, CVSS metrics (
VA:Honly), and CWE-617 (Reachable Assertion) classification describe a crash/reboot denial-of-service after authenticated packet delivery — not a scored memory-corruption confidentiality/integrity breach. This document follows the vendor description and scoring data. Buffer handling may still be part of the underlying defect, but the published impact is availability-only.
| Field | Value |
|---|---|
| CVE ID | CVE-2026-29115 |
| Vendor | Dahua Technology |
| Vulnerability Type | Denial of Service (unexpected reboot) |
| Attack Vector | Network |
| Authentication Required | Yes (high privileges) |
| User Interaction Required | No |
| Privileges Required | High |
| CVSS Version | 4.0 |
| CVSS Base Score | 6.9 — MEDIUM |
| CVSS Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-617 (Reachable Assertion) |
| Remotely Exploitable | Yes |
| Published Date | 2026-06-10 |
| Fix Availability | Firmware builds from March 26, 2026 onward (per vendor guidance) |
Both CVEs were published on 2026-06-10 from the same Dahua PSI disclosure batch. They share structural similarities but differ in scope and attacker model.
| Attribute | CVE-2026-29115 (this advisory) | CVE-2026-29116 |
|---|---|---|
| CVSS 4.0 Score | 6.9 — MEDIUM | 8.7 — HIGH |
| Privileges Required | High (PR:H) | None (PR:N) |
| Affected Families | IPC, SD | IPC, SD, NVR, XVR, EVS, VTO, VTH, ASI, TPC |
| Published (UTC) | 2026-06-10T06:08:21 | 2026-06-10T06:16:34 |
| Observed Outcome | Unexpected reboot (DoS) | Unexpected reboot (DoS) |
| CWE | CWE-617 | CWE-617 |
| Index Title | Buffer Overflow | Cross-Site Scripting (mislabeled) |
Defender takeaway: Patch both issues on overlapping IPC/SD estates. Prioritize 29116 for internet-exposed devices (unauthenticated). Prioritize 29115 where operator or integrator credentials are widely known, stored in VMS databases, or embedded in mobile apps.
| Date | Event |
|---|---|
| ≤ 2026-03-26 | Vulnerable IPC/SD firmware builds in active distribution |
| 2026-03-26 | Vendor fix cutoff — builds produced on or after this date are outside the affected range (per advisory) |
| 2026-06-10T06:08:21 UTC | CVE-2026-29115 published |
| 2026-06-10T06:08:21 UTC | NVD record last modified |
| 2026-06-10T06:16:34 UTC | Related CVE-2026-29116 published (unauthenticated variant) |
| Ongoing | Operators should inventory IPC/SD fleets, patch, and harden credentials |
Dahua has reported a security vulnerability affecting certain models within its IPC and SD product lines. The flaw exists in network-accessible software that accepts authenticated sessions and processes attacker-influenced protocol data without sufficient validation or safe failure handling.
Observed behavior:
What this vulnerability is not (per CVSS metrics):
UI:N).VC:N).VI:N).SC:N, SI:N, SA:N).What distinguishes it from unauthenticated variants:
PR:H). In practice this often maps to administrative or equivalent device-level accounts rather than read-only monitoring users — exact role mapping is product-specific and should be confirmed against vendor documentation.Public vendor text does not disclose the vulnerable function, service name, or exact buffer dimensions. Based on the published CWE, title, and behavior, plausible root-cause categories include: