Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-29115 — Dahua CVE-2026-29115 | Kitploit
Tools/GitHubGitHub/crimsonfiedofficial/cve-2026-29115
Embedded Systems SecurityIoT SecurityVulnerability AnalysisExploitationHardware & IoT Security
GitHubcrimsonfiedofficial/cve-2026-29115

CVE-2026-29115

Dahua CVE-2026-29115

View Repository
152 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-29115 — Dahua Authenticated Remote Denial of Service

CVSS 4.0 Remotely Exploitable Authentication

Advisory type: Vendor-coordinated security disclosure
CVE ID: CVE-2026-29115
Vendor: Dahua Technology
Published: 2026-06-10T06:08:21 UTC
Last Modified: 2026-06-10T06:08:21 UTC
Source: Dahua Product Security Incident (PSI) Trust Center


Table of Contents

  • Executive Summary
  • At a Glance
  • Relationship to CVE-2026-29116
  • Vulnerability Timeline
  • Description
  • Technical Analysis
  • Affected Products
  • CVSS Scoring
  • Vulnerability Scoring Details
  • CWE Classification
  • Attack Prerequisites
  • Exploitation Scenarios
  • Impact Assessment
  • Detection and Indicators of Compromise
  • Mitigation and Remediation
  • Workarounds
  • Vendor Response
  • References
  • Disclaimer
  • Document Revision History

Executive Summary

A medium-severity, authenticated remote denial-of-service vulnerability has been identified in select Dahua IPC (IP camera) and SD (speed dome / PTZ) products. An attacker who already possesses valid device credentials can send a specially crafted network packet to a vulnerable unit. Processing that packet triggers an unhandled exception (consistent with a reachable assertion or fatal error path), causing the device to reboot unexpectedly.

Unlike its sibling disclosure CVE-2026-29116, which requires no authentication, this flaw demands high privileges (PR:H) on the target device. That constraint reduces practical exploitability for opportunistic internet-wide attackers, but the risk remains material in environments where camera credentials are shared, default, leaked, or recoverable — a common condition in legacy CCTV deployments.

The vulnerability does not demonstrate direct confidentiality or integrity impact in the published CVSS vector. Availability impact is rated High, producing a CVSS 4.0 base score of 6.9 (MEDIUM).

Organizations operating affected Dahua IPC or SD hardware with firmware builds prior to March 26, 2026 should patch, rotate credentials, and restrict management-plane access.

Note on advisory labeling: Some indexes title this CVE "Dahua Buffer Overflow." The vendor description, CVSS metrics (VA:H only), and CWE-617 (Reachable Assertion) classification describe a crash/reboot denial-of-service after authenticated packet delivery — not a scored memory-corruption confidentiality/integrity breach. This document follows the vendor description and scoring data. Buffer handling may still be part of the underlying defect, but the published impact is availability-only.


At a Glance


Relationship to CVE-2026-29116

Both CVEs were published on 2026-06-10 from the same Dahua PSI disclosure batch. They share structural similarities but differ in scope and attacker model.

Defender takeaway: Patch both issues on overlapping IPC/SD estates. Prioritize 29116 for internet-exposed devices (unauthenticated). Prioritize 29115 where operator or integrator credentials are widely known, stored in VMS databases, or embedded in mobile apps.


Vulnerability Timeline


Description

Dahua has reported a security vulnerability affecting certain models within its IPC and SD product lines. The flaw exists in network-accessible software that accepts authenticated sessions and processes attacker-influenced protocol data without sufficient validation or safe failure handling.

Observed behavior:

  1. An authenticated remote attacker with high privileges on the device transmits a specially crafted packet over the network.
  2. The device's handler processes the packet and enters an exceptional code path — for example, a failed assertion, unhandled fault, or unrecoverable internal error consistent with CWE-617 (Reachable Assertion).
  3. The exception causes the system to reboot unexpectedly.
  4. The camera or speed dome remains unavailable until the reboot completes. Repeated exploitation can cause sustained denial of service.

What this vulnerability is not (per CVSS metrics):

  • It does not require victim user interaction such as opening a malicious link (UI:N).
  • It does not demonstrate direct confidentiality impact (VC:N).
  • It does not demonstrate direct integrity impact (VI:N).
  • It does not show subsequent-system impact (SC:N, SI:N, SA:N).

What distinguishes it from unauthenticated variants:

  • The attacker must already hold credentials sufficient to satisfy the device's high privilege threshold (PR:H). In practice this often maps to administrative or equivalent device-level accounts rather than read-only monitoring users — exact role mapping is product-specific and should be confirmed against vendor documentation.

Technical Analysis

Root Cause (Inferred)

Public vendor text does not disclose the vulnerable function, service name, or exact buffer dimensions. Based on the published CWE, title, and behavior, plausible root-cause categories include:

CategoryExplanation
Reachable assertion on bad inputAuthenticated code path validates insufficiently and hits assert() or equivalent on malformed lengths or fields.

The published outcome is reboot-level availability loss, not proven remote code execution or data exfiltration in the CVSS record.

Why "Buffer Overflow" May Appear in Titles

CVE titles are not always precise. A buffer overflow class defect can manifest as:

  • Immediate crash (availability impact only)
  • Controlled memory corruption (potential RCE — not scored in this CVE record)

Here, vendor scoring limits impact to availability, suggesting either non-exploitable corruption, abort-before-exploitation, or vendor assessment that practical integrity/confidentiality outcomes are not achieved.

Attack Surface (Authenticated Plane)

Because exploitation requires high privileges, the relevant surface is typically the management and configuration API available after login, not anonymous discovery endpoints. Depending on model and firmware, that may include:

  • Authenticated HTTP/HTTPS configuration APIs
  • Device maintenance and upgrade interfaces
  • PTZ / lens control channels on SD products
  • Proprietary configuration tunnels reachable post-authentication
  • SDK-integrated management sessions used by VMS platforms

Attackers with credentials harvested from VMS databases, installer laptops, or default admin accounts can reach these planes from anywhere the management port is exposed.

IPC vs. SD Operational Differences

ProductTypical DeploymentDoS Impact Nuance
IPCFixed cameras, door-eye, small businessSingle-sensor outage; may break one coverage zone
SDPTZ domes, perimeter trackingLoss of active tracking; preset patrol interruption; larger mechanical subsystem reset latency

SD reboots may take longer to return to calibrated PTZ state, extending effective downtime beyond raw boot time.


Affected Products

Vendor Summary

#VendorProduct FamiliesVersion / Build Guidance
1DahuaIPC / SDAffected: firmware builds before March 26, 2026 (limited to certain models within each family)

Totals: 1 affected vendor · 1 affected product grouping (IPC + SD)

Product Family Reference

FamilyTypical RoleExample Operational Impact
IPCFixed IP camerasLive view loss, recording gaps, analytics dropout
SDSpeed domes / PTZ camerasTracking failure, patrol interruption, preset loss until recalibration

Out-of-Scope Families (This CVE)

The following Dahua lines are not listed for CVE-2026-29115 (though they may be affected by other CVEs such as CVE-2026-29116):

  • NVR, XVR, EVS (recorders / storage)
  • VTO, VTH (video intercom)
  • ASI (access / security interfaces)
  • TPC (thermal / specialty)

Model Scope Caveat

Only certain models within IPC and SD are affected. Operators must verify:

  1. Exact model number
  2. Firmware build date (fixed builds: on or after 2026-03-26)
  3. Official Dahua PSI model matrix

CVSS Scoring

Summary

ScoreVersionSeverityVector
6.94.0MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVSS 4.0 Metric Breakdown

Why PR:H Lowers the Score vs. CVE-2026-29116

PR:H is the primary score differentiator versus the unauthenticated sibling:

FactorEffect
Credential acquisition barrierOpportunistic WAN scanners cannot exploit without secrets
Insider / post-breach threatStill serious when VMS, installers, or defaults provide admin access
Lateral movementCompromised workstation with stored camera passwords becomes exploitation launch point

6.9 MEDIUM should not be read as "low priority everywhere." In credential-weak CCTV environments, authenticated camera attacks are routine.


Vulnerability Scoring Details

Visual summary of the published CVSS 4.0 selector positions:

Exploit Characteristics

root@kitploit:~
Attack Vector:          [Network]  Adjacent  Local  Physical
Attack Complexity:      [Low]      High
Attack Requirements:    [None]     Present
Privileges Required:      None     Low      [High]
User Interaction:       [None]     Passive  Active

Impact on Vulnerable System

root@kitploit:~
Vuln Confidentiality:   [None]     Low      High
Vuln Integrity:         [None]     Low      High
Vuln Availability:      [High]     Low      None

Subsequent System Impact

root@kitploit:~
Subseq Confidentiality: [None]     Low      High
Subseq Integrity:       [None]     Low      High
Subseq Availability:    [None]     Low      High

CWE Classification

#CWE IDNameRelevance
1CWE-617Reachable AssertionUntrusted input reaches a fatal assertion or abort path in privileged code

CWE-617 in Authenticated Contexts

Authenticated vulnerabilities are often dismissed as "only insiders." In surveillance networks:

  • Integrator accounts are shared across customer sites
  • VMS servers store device passwords centrally
  • Default credentials survive for years on isolated VLANs
  • Former employees retain admin access absent rotation

A reachable assertion behind the authenticated management plane is therefore still a material risk, especially paired with credential reuse.

Buffer Overflow vs. CWE-617

If the underlying defect involves memory corruption, CWE-617 may reflect the observable production behavior (fatal abort) rather than the full weakness taxonomy. Defenders should patch regardless of index naming.


Attack Prerequisites

Remotely Exploitable: Yes (once credentials and network path exist)


Exploitation Scenarios

Scenario 1 — Disgruntled Insider

A technician with admin credentials for all site cameras sends crafted packets to IPC endpoints during off-hours, repeatedly rebooting critical coverage zones.

Scenario 2 — Stolen VMS Password Vault

An attacker exfiltrates the camera password database from a compromised Milestone / Genetec / custom VMS host. They remotely reboot every Dahua IPC on the customer's WAN without further privilege escalation.

Scenario 3 — Default Credential Sweeps

An attacker authenticates with factory defaults (admin / known password lists) on internet-exposed cameras, then triggers reboot loops to harass or blind monitoring during a physical intrusion elsewhere on the property.

Scenario 4 — SD PTZ Sabotage During Active Tracking

A stadium speed dome tracks a security event. Authenticated crafted input reboots the SD unit, losing active PTZ tracking and preset positioning during a critical window.

Scenario 5 — Post-Initial-Compromise Lateral Noise

After phishing an installer laptop, an attacker uses stored credentials to disrupt cameras — degrading forensic capture while a separate team conducts physical entry.


Impact Assessment

Technical Impact

DomainRatingDetail
ConfidentialityNone (direct)Not scored in published vector
IntegrityNone (direct)Not scored in published vector
Availability

Business Impact (Contextual)

SectorPotential Consequence
RetailBlind spots during shrink events
TransportationPlatform / concourse camera gaps
Critical infrastructurePerimeter PTZ tracking loss
Corporate campusesParking and entrance coverage dropout

Auth Barrier vs. Real-World Risk

EnvironmentPractical Risk Level
Strong unique creds + no WAN exposureLower — attacker must breach auth first

Detection and Indicators of Compromise

No public packet signature is documented. Focus on authenticated session abuse correlated with reboot events.

Host / Device Indicators

  • Unexpected reboots following authenticated management sessions from unusual source IPs
  • Fatal error or assertion messages in device logs immediately before restart
  • Short uptimes after admin API activity
  • SD units losing PTZ calibration flags after unplanned reboot

Authentication Indicators

  • Admin login successes from geolocations or subnets not used by operators
  • Burst of authenticated API calls from a single account across many cameras
  • Off-hours configuration sessions without change tickets
  • Use of legacy integrator accounts thought to be retired

Network Indicators

  • Management port traffic (HTTP/S, proprietary SDK ports) immediately preceding offline events
  • Repeated identical payload sizes or anomalous request patterns post-login
  • Correlation between VPN egress IP and camera syslog reboot timestamps

Recommended Actions

  • Enable syslog on IPC/SD devices to centralized SIEM
  • Alert on mass disconnect from VMS within short intervals
  • Correlate authentication logs with watchdog reboot events
  • Audit accounts with admin privileges; remove unused integrator logins

Mitigation and Remediation

Primary Remediation — Firmware Update

  1. Inventory all Dahua IPC and SD units with model, serial, and firmware build date.
  2. Flag devices with builds before March 26, 2026.
  3. Obtain fixed firmware from the Dahua PSI Trust Center.
  4. Upgrade during maintenance windows; verify streams, PTZ presets, and analytics after reboot.
  5. Confirm build date in device UI or ONVIF/SDK query post-patch.

Credential Hygiene (Critical for PR:H Flaws)

Network Controls

Coordinated Patching with CVE-2026-29116

On IPC/SD estates, apply firmware that addresses both CVE-2026-29115 and CVE-2026-29116. The unauthenticated issue is strictly worse from an exposure standpoint; authenticated issues remain dangerous where secrets are weak.


Workarounds

No configuration-only workaround is documented that fully removes the vulnerability without upgrading firmware. Until patched:

  1. Rotate and harden credentials — reduces who can meet PR:H.
  2. Restrict management access to trusted subnets and VPN only.
  3. Monitor for reboot loops and block offending sources at the firewall.
  4. Disable remote admin on cameras that only need outbound cloud/P2P connectivity (architecture-dependent).

Vendor Response

Dahua published this issue through its Product Security Incident (PSI) program:

  • Trust Center / PSI: https://www.dahuasecurity.com/about-dahua/trust-center/dahua-psi

Consult the vendor bulletin for:

  • Model-specific affected IPC/SD lists
  • Fixed firmware images and release notes
  • Any additional hardening guidance

References


Disclaimer

This document is an informational security advisory compiled from publicly available CVE metadata and vendor statements. It is intended to assist defenders, integrators, and researchers in understanding CVE-2026-29115 risk and prioritizing remediation.

  • This README does not provide exploit code, crafted packet templates, or attack recipes.
  • Inferred technical analysis is not vendor-confirmed root-cause disclosure.
  • Model and firmware applicability must be verified against official Dahua PSI guidance.
  • The authors are not liable for actions taken based on this document.

Responsible use: Report additional findings through coordinated disclosure (vendor PSI, CERT, or authorized bug bounty programs).


Document Revision History

VersionDateChanges
1.02026-07-11Initial comprehensive advisory README based on CVE-2026-29115 publication data

CVE-2026-29115 · Dahua Technology · CVSS 4.0 6.9 MEDIUM · CWE-617 · IPC / SD

Download Tool
FieldValue
CVE IDCVE-2026-29115
VendorDahua Technology
Vulnerability TypeDenial of Service (unexpected reboot)
Attack VectorNetwork
Authentication RequiredYes (high privileges)
User Interaction RequiredNo
Privileges RequiredHigh
CVSS Version4.0
CVSS Base Score6.9 — MEDIUM
CVSS VectorCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CWECWE-617 (Reachable Assertion)
Remotely ExploitableYes
Published Date2026-06-10
Fix AvailabilityFirmware builds from March 26, 2026 onward (per vendor guidance)
AttributeCVE-2026-29115 (this advisory)CVE-2026-29116
CVSS 4.0 Score6.9 — MEDIUM8.7 — HIGH
Privileges RequiredHigh (PR:H)None (PR:N)
Affected FamiliesIPC, SDIPC, SD, NVR, XVR, EVS, VTO, VTH, ASI, TPC
Published (UTC)2026-06-10T06:08:212026-06-10T06:16:34
Observed OutcomeUnexpected reboot (DoS)Unexpected reboot (DoS)
CWECWE-617CWE-617
Index TitleBuffer OverflowCross-Site Scripting (mislabeled)
DateEvent
≤ 2026-03-26Vulnerable IPC/SD firmware builds in active distribution
2026-03-26Vendor fix cutoff — builds produced on or after this date are outside the affected range (per advisory)
2026-06-10T06:08:21 UTCCVE-2026-29115 published
2026-06-10T06:08:21 UTCNVD record last modified
2026-06-10T06:16:34 UTCRelated CVE-2026-29116 published (unauthenticated variant)
OngoingOperators should inventory IPC/SD fleets, patch, and harden credentials
Buffer mishandling leading to fatal abortOversized or malformed payload exceeds an internal buffer; defensive check fails fatally instead of returning an error.
State machine corruptionCrafted packet drives parser into illegal state; integrity check triggers process termination.
MetricValueMeaning for this CVE
AV (Attack Vector)Network (N)Exploitation over network; remote attackers qualify when management services are reachable
AC (Attack Complexity)Low (L)No special race conditions or environmental constraints indicated
AT (Attack Requirements)None (N)No additional deployment quirks beyond auth + reachability
PR (Privileges Required)High (H)Attacker must hold high-privilege device credentials
UI (User Interaction)None (N)No end-user click or browser action required
VC (Vuln System Confidentiality)None (N)No direct confidentiality loss scored
VI (Vuln System Integrity)None (N)No direct integrity loss scored
VA (Vuln System Availability)High (H)Reboot-class outage
SC / SI / SANoneNo subsequent-system impacts scored
PrerequisiteRequired?Notes
High-privilege device credentialsYesPR:H — admin-class access (product-specific)
Victim user interactionNoNo phishing or browser action needed
Network reachabilityYesManagement or authenticated service port reachable
Prior compromise of another systemHelpful, not mandatoryStolen creds from VMS qualifies
Internet exposureNot requiredIncreases remote exploit feasibility
Knowledge of target modelHelpfulCrafted packet may be model/firmware specific
High
Unexpected reboot; repeatable
Shared integrator password across 500 camerasHigh — single secret enables mass DoS
Internet port-forward with default adminHigh — resembles unauthenticated practical risk
Air-gapped LAN, tight ACLsModerate — insider or lateral movement dependent
ActionRationale
Rotate all camera admin passwordsNeutralizes stolen creds from old VMS exports
Unique password per deviceLimits blast radius of one leaked secret
Disable unused accountsRemoves dormant integrator backdoors
Enforce strong password policyReduces default-credential guessing
Migrate to centralized auth where supportedImproves auditability and revocation
ControlObjective
Segment cameras on dedicated VLANsContain lateral movement
Restrict management ports by source IPOnly VMS and jump hosts may authenticate
Eliminate raw WAN port-forwardingForce VPN or zero-trust access
Disable unused servicesShrink authenticated attack surface
Monitor admin API accessDetect abuse before repeated reboots
ResourceURL
Dahua PSI Trust Centerhttps://www.dahuasecurity.com/about-dahua/trust-center/dahua-psi
NVD Entryhttps://nvd.nist.gov/vuln/detail/CVE-2026-29115
CVE Recordhttps://www.cve.org/CVERecord?id=CVE-2026-29115
Related: CVE-2026-29116https://www.cve.org/CVERecord?id=CVE-2026-29116
CWE-617 Definitionhttps://cwe.mitre.org/data/definitions/617.html
CVSS 4.0 Specificationhttps://www.first.org/cvss/v4.0/specification-document