Executive brief
A vulnerability in certain Dahua security products allows an unauthenticated remote attacker to crash the device. By sending a specifically crafted network packet, the attacker can trigger a system exception that causes the device to reboot unexpectedly. This results in a denial of service, temporarily disabling surveillance or security monitoring capabilities.
Technical details
This vulnerability is classified as a Reachable Assertion (CWE-617). It exists in the network stack or service handling of certain Dahua products, where a specially crafted packet can trigger a logic exception. Because the system does not gracefully handle this exception, it results in an immediate reboot of the hardware. The attack is network-reachable, requires no authentication, and involves no user interaction. Successful exploitation results in a complete loss of availability (Denial of Service) until the device finishes its reboot cycle.
Affected products
- Dahua Technologies Dahua Products
Timeline
- 2026-06-10: disclosed: Initial publication of the vulnerability advisory.
- 2026-06-10: advisory: Dahua PSIRT released security advisory DHCC-SA-202606-001.