CVE-2025-31703: Low severity Dahua Dahua NVR/XVR vulnerability
A vulnerability found in Dahua NVR/XVR device. A third-party malicious attacker with physical access to the device may gain access to a restricted shell via the serial port, and bypasses the shell's authentication mechanism to escalate privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31703?
CVE-2025-31703 is classified as a high severity vulnerability due to the potential for privilege escalation through physical access.
How do I fix CVE-2025-31703?
To mitigate CVE-2025-31703, ensure physical security measures are implemented to restrict access to the Dahua NVR/XVR device.
Who is affected by CVE-2025-31703?
CVE-2025-31703 affects all Dahua NVR/XVR devices that allow physical access to the serial port.
What impact does CVE-2025-31703 have?
CVE-2025-31703 allows an attacker with physical access to escalate privileges by bypassing the authentication mechanism of the shell.
Is CVE-2025-31703 related to remote access vulnerabilities?
No, CVE-2025-31703 specifically requires physical access to the device, making it an access control-related vulnerability.