CVE-2025-31703 PUBLISHED

Assigner: dahua
Reserved: 01.04.2025 Published: 18.03.2026 Updated: 18.03.2026

A vulnerability found in Dahua NVR/XVR device. A third-party malicious attacker with physical access to the device may gain access to a restricted shell via the serial port, and bypasses the shell's authentication mechanism to escalate privileges.

Metrics

CVSS Vector: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
CVSS Score: 2.4

Product Status

Vendor dahua
Product NVR2-4KS3
Versions Default: unaffected
  • Version Versions which Build time prior to 3rd March 2026 is affected
Vendor dahua
Product XVR4232AN-I/T
Versions Default: unaffected
  • Version Versions which Build time prior to 3rd March 2026 is affected
Vendor dahua
Product XVR1B16H-I/T
Versions Default: unaffected
  • Version Versions which Build time prior to 3rd March 2026 is affected

References

Problem Types

  • CWE-305 Authentication bypass by primary weakness CWE

Impacts

  • CAPEC-233 Privilege Escalation