CVE-2017-7927: Dahuasecurity Dh-HCVR4XXX Firmware

High severity, CVSS 7.3. EPSS: 36.7% chance of exploitation in the next 30 days.

A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The use of password hash instead of password for authentication vulnerability was identified, which could allow a malicious user to bypass authentication without obtaining the actual password.

Affected products

  • Dahuasecurity Dh-HCVR4XXX Firmware: affected versions not specified
  • Dahuasecurity Dh-HCVR5XXX Firmware: affected versions not specified
  • Dahuasecurity Dh-Ipc-HDBW13A0SN Firmware: affected versions not specified
  • Dahuasecurity Dh-Ipc-HDBW23A0RN-Zs Firmware: affected versions not specified
  • Dahuasecurity Dh-Ipc-HDW1XXX Firmware: affected versions not specified
  • Dahuasecurity Dh-Ipc-HDW2XXX Firmware: affected versions not specified
  • Dahuasecurity Dh-Ipc-HDW4XXX Firmware: affected versions not specified
  • Dahuasecurity Dh-Ipc-HFW1XXX Firmware: affected versions not specified
  • Dahuasecurity Dh-Ipc-HFW2XXX Firmware: affected versions not specified
  • Dahuasecurity Dh-Ipc-HFW4XXX Firmware: affected versions not specified
  • Dahuasecurity Dh-NVR1XXX Firmware: affected versions not specified
  • Dahuasecurity Dh-SD6CXX Firmware: affected versions not specified
  • Dahuasecurity Dhi-HCVR51A04HE-s3 Firmware: affected versions not specified
  • Dahuasecurity Dhi-HCVR51A08HE-s3 Firmware: affected versions not specified
  • Dahuasecurity Dhi-HCVR58A32S-s2 Firmware: affected versions not specified

Published 2017-05-06. Last modified 2026-06-17.