Home

Description

A vulnerability found in Dahua NVR/XVR device. A third-party malicious attacker with physical access to the device may gain access to a restricted shell via the serial port, and bypasses the shell's authentication mechanism to escalate privileges.

PUBLISHED Reserved 2025-04-01 | Published 2026-03-18 | Updated 2026-03-18 | Assigner dahua




LOW: 2.4CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

Problem types

CWE-305 Authentication bypass by primary weakness

Product status

Default status
unaffected

Versions which Build time prior to 3rd March 2026
affected

Default status
unaffected

Versions which Build time prior to 3rd March 2026
affected

Default status
unaffected

Versions which Build time prior to 3rd March 2026
affected

References

www.dahuasecurity.com/...ility-found-in-dahua-nvr-xvr-device

cve.org (CVE-2025-31703)

nvd.nist.gov (CVE-2025-31703)

Download JSON