Back to search
CVE-2025-31703
Published: Mar 18, 2026
Modified: Mar 18, 2026
PUBLISHED
Description
A vulnerability found in Dahua NVR/XVR device. A third-party malicious attacker with physical access to the device may gain access to a restricted shell via the serial port, and bypasses the shell's authentication mechanism to escalate privileges.
| Vendor | Product | Versions |
|---|---|---|
dahua | NVR2-4KS3 | affected Versions which Build time prior to 3rd March 2026 |
dahua | XVR4232AN-I/T | affected Versions which Build time prior to 3rd March 2026 |
dahua | XVR1B16H-I/T | affected Versions which Build time prior to 3rd March 2026 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now