Junglewise Threat Intelligence

CVE-2026-29114: Dahua Products Sensitive Information Disclosure in CA Root Certificate

CVE-2026-29114 · Severity: info · CVSS 2.3 · Published 2026-06-10

Technologies: Dahua Products. Vendors: Dahua.

Executive brief

A security flaw in certain Dahua devices allows an attacker to obtain the device's root security certificate. If this certificate is manually installed and trusted on employee computers or servers, the attacker could use it to create fake, trusted websites or intercept encrypted communications. This could lead to the theft of login credentials or sensitive data by undermining the digital trust chain between the device and the user.

Technical details

A vulnerability classified as CWE-538 (Insertion of Sensitive Information into Externally-Accessible File or Directory) exists in some Dahua products. An unauthenticated attacker can access and download the device's CA root certificate from an externally accessible location. If a client system has been configured to trust this specific CA root, the attacker can leverage the certificate to perform man-in-the-middle (MitM) attacks or issue fraudulent certificates that the client will recognize as valid. The attack requires network reachability and the precondition that the CA is trusted by the victim's system.

Affected products

  • Dahua Dahua Products

Timeline

  • 2026-06-10: disclosed: Initial publication of the vulnerability advisory.
  • 2026-06-10: advisory: Dahua PSIRT released security advisory DHCC-SA-202606-001.

References

Related threats