CVE Database · CVE-2013-3612
CVSS v3.1
N/A
EPSS
10.30%
Published
Sep 17, 2013
Modified
Apr 28, 2026
Public PoC / Exploit (2)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Dahua DVR appliances have a hardcoded password for (1) the root account and (2) an unspecified "backdoor" account, which makes it easier for remote attackers to obtain administrative access via authorization requests involving (a) ActiveX, (b) a standalone client, or (c) unknown other vectors.
Weaknesses (CWE)
Affected Products (65)
References (2)
...and 15 more