Junglewise Threat Intelligence

CVE-2026-29115: Dahua Products Denial of Service via Reachable Assertion

CVE-2026-29115 · Severity: info · CVSS 6.9 · Published 2026-06-10

Technologies: Dahua Products. Vendors: Dahua.

Executive brief

A vulnerability in certain Dahua security products allows an authorized user to crash the device remotely. By sending a specifically crafted network packet, an attacker can force the system to reboot unexpectedly. This results in a denial of service, temporarily disabling video surveillance or security monitoring capabilities.

Technical details

A Reachable Assertion vulnerability (CWE-617) exists in multiple Dahua products. The flaw is triggered when the system processes a specially crafted network packet, leading to an unhandled exception and an immediate system reboot. Exploitation requires the attacker to be authenticated with high privileges (PR:H) and have network access to the device. Successful exploitation results in a complete loss of availability for the duration of the reboot cycle. Dahua has released a security advisory (DHCC-SA-202606-001) to address the issue.

Affected products

  • Dahua Dahua Products

Timeline

  • 2026-06-10: disclosed
  • 2026-06-10: advisory

References

Related threats