CVE-2025-34059: Dahua Smart Cloud Gateway Registration Management Platform SQL Injection
An SQL injection vulnerability exists in the Dahua Smart Cloud Gateway Registration Management Platform via the username parameter in the /index.php/User/doLogin endpoint. The application fails to properly sanitize user input, allowing unauthenticated attackers to inject arbitrary SQL statements and potentially disclose sensitive information. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34059?
CVE-2025-34059 has a critical severity level due to its potential impact on unauthorized access and data manipulation.
How do I fix CVE-2025-34059?
To fix CVE-2025-34059, ensure that the input validation and sanitization of the username parameter in the /index.php/User/doLogin endpoint is properly implemented.
What systems are affected by CVE-2025-34059?
CVE-2025-34059 affects the Dahua Smart Cloud Gateway Registration Management Platform.
Can CVE-2025-34059 be exploited remotely?
Yes, CVE-2025-34059 can be exploited remotely by unauthenticated attackers due to inadequate input sanitization.
What are the consequences of exploiting CVE-2025-34059?
Exploiting CVE-2025-34059 can lead to unauthorized data access, alteration, and potential compromise of user credentials.