PT-2025-42234 · Dahua · Dahua Embedded Products

CVE-2025-31702

·

Published

2025-10-15

·

Updated

2026-08-21

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Dahua embedded products (affected versions not specified)
Description An improper permission assignment for a critical resource allows a remote attacker with normal user credentials to access data restricted to administrator privileges via a specific HTTP request. This flaw enables access to system-sensitive files and may allow the attacker to tamper with the administrator password, resulting in privilege escalation. Systems configured with only an administrator account are not affected.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-13765
CVE-2025-31702

Affected Products

Dahua Embedded Products