CVE Database
/

CVE-2025-31703

Back to search

CVE-2025-31703

Published: Mar 18, 2026

Modified: Mar 18, 2026

PUBLISHED

Description

A vulnerability found in Dahua NVR/XVR device. A third-party malicious attacker with physical access to the device may gain access to a restricted shell via the serial port, and bypasses the shell's authentication mechanism to escalate privileges.

VendorProductVersions

dahua

NVR2-4KS3

affected
Versions which Build time prior to 3rd March 2026

dahua

XVR4232AN-I/T

affected
Versions which Build time prior to 3rd March 2026

dahua

XVR1B16H-I/T

affected
Versions which Build time prior to 3rd March 2026

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now