Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Maodaner Security

#22977of 53,638
10Total CVSS
Vulnerabilities · 1
PT-2025-34942
10
2025-08-27
Dahua · Dahua Eims · CVE-2024-13985
Name of the Vulnerable Software and Affected Versions: Dahua EIMS versions prior to 2240008 Description: A command injection flaw in Dahua EIMS allows unauthenticated remote attackers to execute arbitrary system commands. This is due to improper input validation in the `captureCommand` parameter of the `/capture handle.action` API endpoint. Crafted HTTP requests can inject OS-level commands, potentially leading to full system compromise. Recommendations: Update Dahua EIMS to version 2240008 or later. As a temporary workaround, restrict access to the `/capture handle.action` API endpoint. Sanitize all input to the `captureCommand` parameter.