CVE-2025-31703
Received
Received - Intake
Authentication Bypass in Dahua NVR/XVR Serial Port Shell
Publication date: 2026-03-18
Last updated on: 2026-03-18
Assigner: Dahua Technologies
Description
Description
A vulnerability found in Dahua NVR/XVR device. A third-party malicious attacker with physical access to the device may gain access to a restricted shell via the serial port, and bypasses the shell's authentication mechanism to escalate privileges.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| dahua | nvr2-4ks3 | to 2026-03-03 (exc) |
| dahua | xvr4232an-i | to 2026-03-03 (exc) |
| dahua | xvr1b16h-i | to 2026-03-03 (exc) |
| dahua | dh_nvr2x-4ks3_multilang_v4.005.0000000.6.r.260304 | to 2026-03-03 (exc) |
| dahua | dh_xvr4x32-it_multilang_v4.004.0000001.1.r.260304 | to 2026-03-03 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-305 | The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error. |