S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-3836 Scanner

Detects 'Unrestricted File Upload' vulnerability in Dahua Smart Park Management affects v. up to 20230713.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
6.3
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient.
Description

A vulnerability classified as critical was found in Dahua Smart Park Management up to 20230713. This vulnerability affects unknown code of the file /emap/devicePoint_addImgIco?hasSubsystem=true. The manipulation of the argument upload leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-235162 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
Smart Park Managementby Dahua
20230713
Updated Sep 18, 2026View on NVD →
Detail

Dahua Smart Park Management is a software platform developed for managing and monitoring smart parks. The platform offers a range of features, including real-time surveillance, access control, and parking management. It is widely used by park owners and managers to ensure the safety and security of their premises.

Despite its popularity, the Dahua Smart Park Management system is not immune to cybersecurity threats. A critical vulnerability, identified as CVE-2023-3836, was recently discovered in the system. Specifically, the issue affects the unknown code of the file /emap/devicePoint_addImgIco?hasSubsystem=true. The vulnerability arises due to unrestricted upload manipulation of the argument upload, which can be initiated remotely.

When exploited, this vulnerability can have severe consequences. Attackers can leverage this flaw to upload and execute malicious code on the affected system. This can result in unauthorized access to sensitive data, unauthorized changes to system settings, and even the complete takeover of the system.

For those concerned about cybersecurity, s4e.io offers a wealth of resources and features. With premium features, users can easily and quickly detect vulnerabilities in their digital assets and take steps to mitigate them. In a world where cybersecurity threats are increasingly common, it pays to take a proactive approach to protect your assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, preventative measures must be implemented promptly. Here are some recommended precautions:

  • Conduct regular security assessments to identify and address vulnerabilities in the system
  • Implement access controls to restrict access to sensitive areas of the system
  • Install the latest security updates and patches to keep the system up-to-date
  • Use intrusion detection and prevention systems to detect and block attacks
  • Deploy firewalls to restrict unauthorized access to the system

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.