Bitdefender disclosed two serious vulnerabilities in Dahua camera firmware, tracked as CVE-2025-31700 and CVE-2025-31701, that can be exploited by an unauthenticated attacker to achieve remote code execution or trigger denial of service. The flaws affect the Dahua Hero C1 Smart Camera and multiple Dahua IPC, SD, and TPC camera series, with all firmware released before 2025-04-16 reported as vulnerable.
Both vulnerabilities carry a CVSS 3.1 score of 8.1, and CSIRT.SK warned that successful exploitation could compromise device integrity and the security of monitored premises. Administrators and camera owners were urged to apply Dahua’s available firmware updates promptly to reduce the risk of takeover or service disruption across exposed surveillance deployments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK published an alert stating that Dahua had provided security updates for the affected cameras and urged administrators and owners to apply them. The notice emphasized the risk to system integrity and monitored premises if the flaws were exploited.
Bitdefender's IoT Research Team disclosed CVE-2025-31700 and CVE-2025-31701, two serious vulnerabilities affecting Dahua security camera firmware. The flaws could allow an unauthenticated attacker to achieve remote code execution or denial of service.
CSIRT.SK reported that all firmware versions released before 2025-04-16 for multiple Dahua IPC, SD, and TPC camera series are vulnerable to CVE-2025-31700 and CVE-2025-31701.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.