Dahuasecurity manufactures a broad range of surveillance and digital security appliances, including network video recorders and storage systems widely deployed in security and monitoring infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency to acquire public exploit code, reflecting the internet-facing nature and privileged access context of these devices. The exposure concentrates across product lines such as the DSS series recorders and storage units and recurs through authentication and access-control weaknesses—including missing authentication for critical functions, improper input validation, and improper access control—that are characteristic of embedded appliances with legacy authentication models. Defenders should prioritize inventory and network segmentation of these devices, particularly internet-exposed instances, and track the vendor's advisories closely for patching. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dahuasecurity over time
Signals from CVEs in this vendor scope (58 CVEs).
58 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-33044CRITICAL The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing maliciou | Sep 15, 2021 | 9.8 | 98 | YES | YES |
CVE-2021-33045CRITICAL The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing maliciou | Sep 15, 2021 | 9.8 | 97 | YES | YES |
CVE-2013-6117HIGH Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear l | Jul 11, 2014 | 7.5 | 81 | NO | YES |
CVE-2023-3836CRITICAL A vulnerability classified as critical was found in Dahua Smart Park Management up to 20230713. This vulnerability affects unknown code of the file /emap/devicePoint_addImgIco?hasS | Jul 22, 2023 | 9.8 | 79 | NO | YES |
CVE-2017-7925CRITICAL A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2X | May 6, 2017 | 9.8 | 70 | NO | YES |
CVE-2017-6343HIGH The web interface on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 | Feb 27, 2017 | 8.1 | 60 | NO | NO |
CVE-2017-7927HIGH A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, | May 6, 2017 | 7.3 | 44 | NO | NO |
CVE-2013-3612HIGH Dahua DVR appliances have a hardcoded password for (1) the root account and (2) an unspecified "backdoor" account, which makes it easier for remote attackers to obtain administrati | Sep 17, 2013 | 10.0 | 39 | NO | YES |
CVE-2017-6342CRITICAL An issue was discovered on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017- | Feb 27, 2017 | 9.8 | 36 | NO | NO |
CVE-2013-3614HIGH Dahua DVR appliances have a small value for the maximum password length, which makes it easier for remote attackers to obtain access via a brute-force attack. | Sep 17, 2013 | 9.3 | 36 | NO | YES |
Signals from CVEs in this vendor scope (58 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dahuasecurity.
Media articles that mention a CVE ID that affects a product developed by Dahuasecurity — matched by CVE ID, not by vendor name.