A vulnerability found in Dahua NVR/XVR device. A third-party malicious attacker with physical access to the device may gain access to a restricted shell via the serial port, and bypasses the shell's authentication mechanism to escalate privileges.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 18 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dahua
Dahua nvr2-4ks3 Dahua xvr1b16h-i/t Dahua xvr4232an-i/t |
|
| Vendors & Products |
Dahua
Dahua nvr2-4ks3 Dahua xvr1b16h-i/t Dahua xvr4232an-i/t |
Wed, 18 Mar 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability found in Dahua NVR/XVR device. A third-party malicious attacker with physical access to the device may gain access to a restricted shell via the serial port, and bypasses the shell's authentication mechanism to escalate privileges. | |
| Weaknesses | CWE-305 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: dahua
Published:
Updated: 2026-03-18T07:13:21.911Z
Reserved: 2025-04-01T05:57:11.783Z
Link: CVE-2025-31703
No data.
Status : Received
Published: 2026-03-18T08:16:26.810
Modified: 2026-03-18T08:16:26.810
Link: CVE-2025-31703
No data.
OpenCVE Enrichment
Updated: 2026-03-18T10:41:44Z
Weaknesses