Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/crimsonfiedofficial/cve-2026-29116
IoT SecurityVulnerability AnalysisExploitationNetwork SecurityHardware & IoT Security
GitHubcrimsonfiedofficial/cve-2026-29116

CVE-2026-29116

Dahua CVE-2026-29116

View Repository
11192 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-29116 — Dahua Unauthenticated Remote Denial of Service

CVSS 4.0 Remotely Exploitable Authentication

Advisory type: Vendor-coordinated security disclosure
CVE ID: CVE-2026-29116
Vendor: Dahua Technology
Published: 2026-06-10T06:16:34 UTC
Last Modified: 2026-06-10T06:16:34 UTC
Source: Dahua Product Security Incident (PSI) Trust Center


Table of Contents

  • Executive Summary
  • At a Glance
  • Vulnerability Timeline
  • Description
  • Technical Analysis
  • Affected Products
  • CVSS Scoring
  • Vulnerability Scoring Details
  • CWE Classification
  • Attack Prerequisites
  • Exploitation Scenarios
  • Impact Assessment
  • Detection and Indicators of Compromise
  • Mitigation and Remediation
  • Workarounds
  • Vendor Response
  • References
  • Disclaimer
  • Document Revision History

Executive Summary

A high-severity, unauthenticated remote denial-of-service vulnerability has been identified in multiple Dahua security and surveillance product lines. An attacker on the network — including the public internet when devices are exposed — can send a specially crafted network packet to a vulnerable device. Processing that packet triggers an unhandled exception (consistent with a reachable assertion or fatal error path), causing the device to reboot unexpectedly.

Because no credentials are required and attack complexity is low, this vulnerability is straightforward to exploit at scale. Repeated exploitation can produce sustained outages across cameras, recorders, intercom endpoints, and related infrastructure. While the flaw does not directly compromise confidentiality or integrity of stored data, the availability impact is rated High, yielding a CVSS 4.0 base score of 8.7 (HIGH).

Organizations operating Dahua IPC, SD, NVR, XVR, EVS, VTO, VTH, ASI, or TPC hardware with firmware builds prior to March 26, 2026 should treat patching or network isolation as a priority.

Note on advisory labeling: Some third-party indexes list this CVE under a "Cross-Site Scripting" title. The official description, CVSS vector (VA:H with no confidentiality or integrity impact), and CWE-617 classification are consistent with an unauthenticated network-triggered crash/reboot (DoS), not a browser-based XSS condition. This document follows the vendor description and scoring data.


At a Glance

FieldValue
CVE IDCVE-2026-29116
VendorDahua Technology
Vulnerability TypeDenial of Service (unexpected reboot)
Attack VectorNetwork
Authentication RequiredNo
User Interaction RequiredNo
Privileges RequiredNone
CVSS Version4.0
CVSS Base Score8.7 — HIGH
CVSS VectorCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CWECWE-617 (Reachable Assertion)
Remotely ExploitableYes
Published Date2026-06-10
Fix AvailabilityFirmware builds from March 26, 2026 onward (per vendor guidance)

Vulnerability Timeline

DateEvent
≤ 2026-03-26Vulnerable firmware builds in active distribution
2026-03-26Vendor fix cutoff — builds produced on or after this date are outside the affected range (per advisory)
2026-06-10T06:16:34 UTCCVE-2026-29116 published
2026-06-10T06:16:34 UTCNVD record last modified
2026-06-10Dahua PSI Trust Center advisory published
OngoingOperators should inventory, patch, and segment affected estates

Description

Dahua has reported a security vulnerability affecting a subset of products across its surveillance and access portfolio. The flaw resides in network-facing software that handles inbound traffic without adequately validating or safely handling malformed or adversarial input.

Observed behavior:

  1. An unauthenticated remote attacker transmits a specially crafted packet to a vulnerable device over the network.
  2. The device's network service or internal handler processes the packet and enters an exceptional code path — for example, a failed assertion, unhandled fault, or unrecoverable internal error consistent with CWE-617 (Reachable Assertion).
  3. The exception propagates in a way that causes the system to reboot unexpectedly.
  4. The device is unavailable until the reboot cycle completes. Under repeated attack, the device may remain in a persistent denial-of-service state.

What this vulnerability is not (per CVSS metrics):

  • It does not require the victim to open a web page or click a link (UI:N).
  • It does not require attacker credentials (PR:N).
  • It does not demonstrate direct confidentiality or integrity impact on the vulnerable component (VC:N, VI:N).
  • It does not show subsequent-system impact in the published vector (SC:N, SI:N, SA:N).

The primary risk is loss of availability — cameras stop streaming, recorders stop recording, intercoms go offline, and automated workflows depending on those devices fail.


Technical Analysis

Root Cause (Inferred)

Public vendor text does not disclose the exact function or protocol endpoint. Based on the published CWE and behavior, the most probable root-cause categories are:

CategoryExplanation
Reachable assertionA debug or integrity assert() (or equivalent) remains enabled in production firmware and can be triggered by malformed input.
Uncaught fatal exceptionParser or session state machine throws/crashes on unexpected field values, lengths, or protocol states.
Resource or bounds mishandlingCrafted packet causes an out-of-bounds access or invalid memory operation detected at runtime, terminating the process or kernel path.

Any of the above can cascade into a full device reboot if the failure occurs in a critical daemon, the main application supervisor, or a kernel-adjacent component without graceful recovery.

Attack Surface

Because the attack vector is Network and no privileges are required, any reachable service that parses attacker-supplied network input on affected firmware may be implicated. In Dahua deployments, that commonly includes — but is not limited to —:

  • Device discovery and registration services
  • Proprietary P2P / tunnel / relay handshake handlers
  • HTTP/HTTPS management interfaces (where raw or chunked requests are mishandled)
  • RTSP / ONVIF / SIP-adjacent stacks (product-dependent)
  • Intercom and door station signaling (VTO/VTH lines)

Important: The vendor advisory does not name a single port or URI. Defenders should assume any exposed network listener on vulnerable firmware could be relevant until patched.

Reboot vs. Process Restart

From an operator's perspective both outcomes look like "the camera went offline," but they differ operationally:

Download Tool