PT-2025-34942 · Dahua · Dahua Eims

Maodaner Security

·

Published

2025-08-27

·

Updated

2025-08-27

·

CVE-2024-13985

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions: Dahua EIMS versions prior to 2240008
Description: A command injection flaw in Dahua EIMS allows unauthenticated remote attackers to execute arbitrary system commands. This is due to improper input validation in the captureCommand parameter of the /capture handle.action API endpoint. Crafted HTTP requests can inject OS-level commands, potentially leading to full system compromise.
Recommendations: Update Dahua EIMS to version 2240008 or later. As a temporary workaround, restrict access to the /capture handle.action API endpoint. Sanitize all input to the captureCommand parameter.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-13985

Affected Products

Dahua Eims