Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 24 Mar 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Privilege Escalation via Serial Port Restricted Shell in Dahua NVR/XVR Devices |
Wed, 18 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dahua
Dahua nvr2-4ks3 Dahua xvr1b16h-i/t Dahua xvr4232an-i/t |
|
| Vendors & Products |
Dahua
Dahua nvr2-4ks3 Dahua xvr1b16h-i/t Dahua xvr4232an-i/t |
Wed, 18 Mar 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability found in Dahua NVR/XVR device. A third-party malicious attacker with physical access to the device may gain access to a restricted shell via the serial port, and bypasses the shell's authentication mechanism to escalate privileges. | |
| Weaknesses | CWE-305 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: dahua
Published:
Updated: 2026-03-18T14:09:28.123Z
Reserved: 2025-04-01T05:57:11.783Z
Link: CVE-2025-31703
Updated: 2026-03-18T14:09:24.012Z
Status : Awaiting Analysis
Published: 2026-03-18T08:16:26.810
Modified: 2026-03-18T14:52:44.227
Link: CVE-2025-31703
No data.
OpenCVE Enrichment
Updated: 2026-03-24T10:59:13Z