Dahua Technologies is a surveillance and security camera manufacturer whose disclosed vulnerabilities center on network video recorders and IP camera products such as the N54A4P and DH-IPC-HX863X series. The recurring weakness classes—classic buffer overflows, missing authentication for critical functions, and associated input-validation gaps—reflect the firmware and embedded-application attack surface typical of networked security appliances. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dahua Technologies over time
Of all the CVEs published by Dahua Technologies as a CNA, 4.1% affect products that Dahua Technologies develops as a vendor.
Of all the CVEs published that affect products developed by Dahua Technologies, 66.7% are self-published by Dahua Technologies as a CNA.
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-3948HIGH The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0.R, Dahua DH-IPC HX883X and DH-IPC-HX863X V2.622.0000000.7.R | Jul 29, 2019 | 7.5 | 50 | NO | YES |
CVE-2020-9499HIGH Some Dahua products have buffer overflow vulnerabilities. After the successful login of the legal account, the attacker sends a specific DDNS test command, which may cause the devi | Apr 9, 2020 | 7.2 | 25 | NO | NO |
CVE-2020-9500MEDIUM Some products of Dahua have Denial of Service vulnerabilities. After the successful login of the legal account, the attacker sends a specific log query command, which may cause the | Apr 9, 2020 | 4.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dahua Technologies.
Media articles that mention a CVE ID that affects a product developed by Dahua Technologies — matched by CVE ID, not by vendor name.