Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Google is experimenting with machine learning power age estimation technology in the US

2025 What Gartner® MagicQuadrant™ reveals

UNC2891 violates ATM network via 4G Raspberry Pi and attempts Caketap rootkit for fraud

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Enabling remote hijacking via critical duffer camera defect ONVIF and file upload exploit
Identity

Enabling remote hijacking via critical duffer camera defect ONVIF and file upload exploit

userBy userJuly 30, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

July 30, 2025Ravi LakshmananFirmware security/vulnerabilities

Important Duffer Camera Flaws

Cybersecurity researchers have disclosed critical security flaws that have now been patched in the firmware of Dahua smart cameras, allowing attackers to hijack control of sensitive devices.

“The flaws affecting the device’s ONVIF protocol and file upload handlers allow unauthorized attackers to execute arbitrary commands remotely and effectively take over the device,” Bitdefender said in a report shared with Hacker News.

Vulnerabilities tracked as CVE-2025-31700 and CVE-2025-31701 (CVSS score: 8.1) affect the following devices running versions with build timestamps by April 16, 2025 –

IPC-1XXX Series IPC-2XXX Series IPC-WX Series IPC-ECXX Series SD3A Series SD2A Series SD3D Series SDT2A Series SD2C Series

Cybersecurity

Users log in to the device’s web interface and[>[>]Note that you can view the build times by going to System Information -> Version.

Both drawbacks are classified as buffer overflow vulnerabilities that can be exploited by sending specially crafted malicious packets, resulting in denial of service or remote code execution (RCE).

Specifically, CVE-2025-31700 is described as a stack-based buffer overflow for Open Network Video Interface Forum (ONVIF) request handlers, while CVE-2025-31701 is about an overflow bug in the RPC file upload handler.

“Some devices may have protection mechanisms deployed, such as Address Space Layout Randomization (ASLR), which reduces the likelihood of successful RCE exploitation,” Dahua said in an alert released last week. “But denial of service (DOS) attacks continue to be a concern.”

Given that these models are used for video surveillance for retail, casinos, warehouses and residential use, flaws can have serious consequences as they are recognized and exploitable by local networks.

“Devices exposed to the internet via port forwarding or UPNP are particularly at risk,” says the Romanian cybersecurity company. “The success of the exploit provides root-level access to the camera without user interaction. The exploit path bypasses firmware integrity checks, allowing attackers to load unsigned payloads or persist through custom daemons, making cleanup difficult.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleObservation continues to adapt to a changing world of software observability
Next Article $23 million to bring Air Lands EVTOLS to the US
user
  • Website

Related Posts

2025 What Gartner® MagicQuadrant™ reveals

July 31, 2025

UNC2891 violates ATM network via 4G Raspberry Pi and attempts Caketap rootkit for fraud

July 31, 2025

Alert fatigue, data overload, and traditional SIEM falls

July 31, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Google is experimenting with machine learning power age estimation technology in the US

2025 What Gartner® MagicQuadrant™ reveals

UNC2891 violates ATM network via 4G Raspberry Pi and attempts Caketap rootkit for fraud

Alert fatigue, data overload, and traditional SIEM falls

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

New Internet Era: Berners-Lee Sets the Pace as Zuckerberg Pursues Metaverse

TwinH Transforms Belgian Student Life: Hendrik’s Journey to Secure Digital Identity

Tim Berners-Lee Unveils the “Missing Link”: How the Web’s Architect Is Building AI’s Trusted Future

Dispatch from London Tech Week: Keir Starmer, The Digital Twin Boom, and FySelf’s Game-Changing TwinH

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.