S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jan 18, 2024

CVE-2017-7925 Scanner

CVE-2017-7925 scanner - Configuration File Disclosure vulnerability in Dahua Security

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-7925
9.8
CVSS

A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The password in configuration file vulnerability was identified, which could lead to a malicious user assuming the identity of a privileged user and gaining access to sensitive information.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Dahua Technology Co., Ltd Digital Video Recorders and IP Camerasby n/a
Dahua Technology Co., Ltd Digital Video Recorders and IP Cameras
Updated Aug 22, 2026View on NVD →
Detail

Dahua Security is a brand that produces a wide range of security cameras and surveillance systems. These devices are utilized in various settings including residential, commercial, and industrial spaces for monitoring and protecting assets. Dahua Security products are designed to provide high-quality and reliable surveillance in diverse environments.

CVE-2017-7925 is a vulnerability that was detected in a range of Dahua Security products, including DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. This vulnerability relates to the password in the configuration file and can be exploited to gain access to sensitive information.

When exploited, this vulnerability can be highly detrimental, as it allows for a malicious actor to impersonate a privileged user and obtain access to sensitive data. This can include video footage and other data that may compromise the overall security of a system. It can also lead to loss of confidential information or data breaches.

Thanks to the advanced features of the s4e.io platform, readers of this article can easily and quickly learn about vulnerabilities in their digital assets. This platform can help individuals and businesses identify potential security risks and take steps to mitigate them before they can be exploited. By utilizing state-of-the-art tools and resources, s4e.io can provide comprehensive risk assessments and tailored solutions to defend against cyber threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, several precautions can be taken, including:

  • Changing the default passwords for any Dahua Security products
  • Keeping all software up to date with the latest security patches
  • Avoiding the use of default login credentials and creating strong passwords
  • Disabling remote access to surveillance systems when not required
  • Regularly monitoring system logs for unusual activity or unauthorized access

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-7925 scanner - Configuration File Disclosure vulnerability in Dahua Security S4E