Executive brief
A vulnerability in certain Dahua security products allows an authorized user to crash the device remotely. By sending a specifically crafted network packet, an attacker can force the system to reboot unexpectedly. This results in a denial of service, temporarily disabling video surveillance or security monitoring capabilities.
Technical details
A Reachable Assertion vulnerability (CWE-617) exists in multiple Dahua products. The flaw is triggered when the system processes a specially crafted network packet, leading to an unhandled exception and an immediate system reboot. Exploitation requires the attacker to be authenticated with high privileges (PR:H) and have network access to the device. Successful exploitation results in a complete loss of availability for the duration of the reboot cycle. Dahua has released a security advisory (DHCC-SA-202606-001) to address the issue.
Affected products
- Dahua Dahua Products
Timeline
- 2026-06-10: disclosed
- 2026-06-10: advisory