Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Dahuasecurity

First CVE: Sep 17, 2013Active for: 13 yearsTotal CVEs: 58
59.4
VTI Score
TOP TARGET

Dahuasecurity manufactures a broad range of surveillance and digital security appliances, including network video recorders and storage systems widely deployed in security and monitoring infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency to acquire public exploit code, reflecting the internet-facing nature and privileged access context of these devices. The exposure concentrates across product lines such as the DSS series recorders and storage units and recurs through authentication and access-control weaknesses—including missing authentication for critical functions, improper input validation, and improper access control—that are characteristic of embedded appliances with legacy authentication models. Defenders should prioritize inventory and network segmentation of these devices, particularly internet-exposed instances, and track the vendor's advisories closely for patching. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
58
Total CVEs
More Total CVEs than 99% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
3.4%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Dahuasecurity over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 17, 2013
12 years ago
Most Recent CVE
Jul 31, 2024
723 days ago

Products(748 total)

Top CVEs

Signals from CVEs in this vendor scope (58 CVEs).

58 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-33044CRITICAL
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing maliciou
Sep 15, 20219.898YESYES
CVE-2021-33045CRITICAL
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing maliciou
Sep 15, 20219.897YESYES
CVE-2013-6117HIGH
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear l
Jul 11, 20147.581NOYES
CVE-2023-3836CRITICAL
A vulnerability classified as critical was found in Dahua Smart Park Management up to 20230713. This vulnerability affects unknown code of the file /emap/devicePoint_addImgIco?hasS
Jul 22, 20239.879NOYES
CVE-2017-7925CRITICAL
A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2X
May 6, 20179.870NOYES
CVE-2017-6343HIGH
The web interface on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19
Feb 27, 20178.160NONO
CVE-2017-7927HIGH
A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX,
May 6, 20177.344NONO
CVE-2013-3612HIGH
Dahua DVR appliances have a hardcoded password for (1) the root account and (2) an unspecified "backdoor" account, which makes it easier for remote attackers to obtain administrati
Sep 17, 201310.039NOYES
CVE-2017-6342CRITICAL
An issue was discovered on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-
Feb 27, 20179.836NONO
CVE-2013-3614HIGH
Dahua DVR appliances have a small value for the maximum password length, which makes it easier for remote attackers to obtain access via a brute-force attack.
Sep 17, 20139.336NOYES
View all 58 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products58 CVEs
28%
48%
19%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (3.4%)
Network49 (84.5%)
Unknown6 (10.3%)
Physical0 (0.0%)
Adjacent Network1 (1.7%)
Attack Complexity
Low40 (69.0%)
High12 (20.7%)
Unknown6 (10.3%)
User Interaction
None51 (87.9%)
Unknown6 (10.3%)
Required1 (1.7%)
Privileges Required
Low9 (15.5%)
High6 (10.3%)
None37 (63.8%)
Unknown6 (10.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (58 CVEs).

CISA KEV
2 CVEs
3.4% of CVEs· 99th percentile
Metasploit
1 CVE
1.7% of CVEs· 97th percentile
Nuclei
4 CVEs
6.9% of CVEs· 96th percentile
ExploitDB
5 CVEs
8.6% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Dahuasecurity.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Dahuasecurity — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Dahuasecurity's Products

View all 5 CNAs →

Top CWEs