Junglewise Threat Intelligence

CVE-2026-29116: Dahua Products Denial of Service via Reachable Assertion

CVE-2026-29116 · Severity: info · CVSS 8.7 · Published 2026-06-10

Technologies: Dahua Technologies Dahua Products.

Executive brief

A vulnerability in certain Dahua security products allows an unauthenticated remote attacker to crash the device. By sending a specifically crafted network packet, the attacker can trigger a system exception that causes the device to reboot unexpectedly. This results in a denial of service, temporarily disabling surveillance or security monitoring capabilities.

Technical details

This vulnerability is classified as a Reachable Assertion (CWE-617). It exists in the network stack or service handling of certain Dahua products, where a specially crafted packet can trigger a logic exception. Because the system does not gracefully handle this exception, it results in an immediate reboot of the hardware. The attack is network-reachable, requires no authentication, and involves no user interaction. Successful exploitation results in a complete loss of availability (Denial of Service) until the device finishes its reboot cycle.

Affected products

  • Dahua Technologies Dahua Products

Timeline

  • 2026-06-10: disclosed: Initial publication of the vulnerability advisory.
  • 2026-06-10: advisory: Dahua PSIRT released security advisory DHCC-SA-202606-001.

References