
Dahua CVE-2026-29116
Advisory type: Vendor-coordinated security disclosure
CVE ID: CVE-2026-29116
Vendor: Dahua Technology
Published: 2026-06-10T06:16:34 UTC
Last Modified: 2026-06-10T06:16:34 UTC
Source: Dahua Product Security Incident (PSI) Trust Center
A high-severity, unauthenticated remote denial-of-service vulnerability has been identified in multiple Dahua security and surveillance product lines. An attacker on the network — including the public internet when devices are exposed — can send a specially crafted network packet to a vulnerable device. Processing that packet triggers an unhandled exception (consistent with a reachable assertion or fatal error path), causing the device to reboot unexpectedly.
Because no credentials are required and attack complexity is low, this vulnerability is straightforward to exploit at scale. Repeated exploitation can produce sustained outages across cameras, recorders, intercom endpoints, and related infrastructure. While the flaw does not directly compromise confidentiality or integrity of stored data, the availability impact is rated High, yielding a CVSS 4.0 base score of 8.7 (HIGH).
Organizations operating Dahua IPC, SD, NVR, XVR, EVS, VTO, VTH, ASI, or TPC hardware with firmware builds prior to March 26, 2026 should treat patching or network isolation as a priority.
Note on advisory labeling: Some third-party indexes list this CVE under a "Cross-Site Scripting" title. The official description, CVSS vector (
VA:Hwith no confidentiality or integrity impact), and CWE-617 classification are consistent with an unauthenticated network-triggered crash/reboot (DoS), not a browser-based XSS condition. This document follows the vendor description and scoring data.
| Field | Value |
|---|---|
| CVE ID | CVE-2026-29116 |
| Vendor | Dahua Technology |
| Vulnerability Type | Denial of Service (unexpected reboot) |
| Attack Vector | Network |
| Authentication Required | No |
| User Interaction Required | No |
| Privileges Required | None |
| CVSS Version | 4.0 |
| CVSS Base Score | 8.7 — HIGH |
| CVSS Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-617 (Reachable Assertion) |
| Remotely Exploitable | Yes |
| Published Date | 2026-06-10 |
| Fix Availability | Firmware builds from March 26, 2026 onward (per vendor guidance) |
| Date | Event |
|---|---|
| ≤ 2026-03-26 | Vulnerable firmware builds in active distribution |
| 2026-03-26 | Vendor fix cutoff — builds produced on or after this date are outside the affected range (per advisory) |
| 2026-06-10T06:16:34 UTC | CVE-2026-29116 published |
| 2026-06-10T06:16:34 UTC | NVD record last modified |
| 2026-06-10 | Dahua PSI Trust Center advisory published |
| Ongoing | Operators should inventory, patch, and segment affected estates |
Dahua has reported a security vulnerability affecting a subset of products across its surveillance and access portfolio. The flaw resides in network-facing software that handles inbound traffic without adequately validating or safely handling malformed or adversarial input.
Observed behavior:
What this vulnerability is not (per CVSS metrics):
UI:N).PR:N).VC:N, VI:N).SC:N, SI:N, SA:N).The primary risk is loss of availability — cameras stop streaming, recorders stop recording, intercoms go offline, and automated workflows depending on those devices fail.
Public vendor text does not disclose the exact function or protocol endpoint. Based on the published CWE and behavior, the most probable root-cause categories are:
| Category | Explanation |
|---|---|
| Reachable assertion | A debug or integrity assert() (or equivalent) remains enabled in production firmware and can be triggered by malformed input. |
| Uncaught fatal exception | Parser or session state machine throws/crashes on unexpected field values, lengths, or protocol states. |
| Resource or bounds mishandling | Crafted packet causes an out-of-bounds access or invalid memory operation detected at runtime, terminating the process or kernel path. |
Any of the above can cascade into a full device reboot if the failure occurs in a critical daemon, the main application supervisor, or a kernel-adjacent component without graceful recovery.
Because the attack vector is Network and no privileges are required, any reachable service that parses attacker-supplied network input on affected firmware may be implicated. In Dahua deployments, that commonly includes — but is not limited to —:
Important: The vendor advisory does not name a single port or URI. Defenders should assume any exposed network listener on vulnerable firmware could be relevant until patched.
From an operator's perspective both outcomes look like "the camera went offline," but they differ operationally: