CVE-2017-7925: Dahuasecurity Dh-HCVR4XXX Firmware

Critical severity, CVSS 9.8. EPSS: 51.4% chance of exploitation in the next 30 days.

A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The password in configuration file vulnerability was identified, which could lead to a malicious user assuming the identity of a privileged user and gaining access to sensitive information.

Affected products

  • Dahuasecurity Dh-HCVR4XXX Firmware: affected versions not specified
  • Dahuasecurity Dh-HCVR5XXX Firmware: affected versions not specified
  • Dahuasecurity Dh-Ipc-HDBW13A0SN Firmware: affected versions not specified
  • Dahuasecurity Dh-Ipc-HDBW23A0RN-Zs Firmware: affected versions not specified
  • Dahuasecurity Dh-Ipc-HDW1XXX Firmware: affected versions not specified
  • Dahuasecurity Dh-Ipc-HDW2XXX Firmware: affected versions not specified
  • Dahuasecurity Dh-Ipc-HDW4XXX Firmware: affected versions not specified
  • Dahuasecurity Dh-Ipc-HFW1XXX Firmware: affected versions not specified
  • Dahuasecurity Dh-Ipc-HFW2XXX Firmware: affected versions not specified
  • Dahuasecurity Dh-Ipc-HFW4XXX Firmware: affected versions not specified
  • Dahuasecurity Dh-NVR1XXX Firmware: affected versions not specified
  • Dahuasecurity Dh-SD6CXX Firmware: affected versions not specified
  • Dahuasecurity Dhi-HCVR51A04HE-s3 Firmware: affected versions not specified
  • Dahuasecurity Dhi-HCVR51A08HE-s3 Firmware: affected versions not specified
  • Dahuasecurity Dhi-HCVR58A32S-s2 Firmware: affected versions not specified

Published 2017-05-06. Last modified 2026-06-17.