CVE-2013-6117 is an authentication bypass vulnerability in Dahua DVR firmware versions 2.608.0000.0 and 2.608.GV00.0. Remote attackers can exploit this flaw by sending crafted requests to TCP port 37777, allowing them to bypass authentication mechanisms. Successful exploitation enables attackers to obtain sensitive information, including user credentials, change user passwords, clear log files, and perform other privileged actions on the device.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit auxiliary module, dahua_dvr_auth_bypass.rb, targeting Dahua DVR/NVR devices vulnerable to CVE-2013-6117. Because it is a Metasploit module, the relevant analysis is limited to this one exploit file. The module is not merely a detector: it performs active unauthenticated interaction with the target over Dahua's proprietary TCP protocol on port 37777 and can also optionally probe the HTTP/HTTPS management interface. The module supports multiple actions to extract sensitive information from a vulnerable device, including firmware version, serial number, user accounts, groups, channel/camera information, DDNS settings, email settings, and NAS settings. It also includes a RESET action to change an existing user's password, with an option to generate a random password if none is supplied, and a CLEAR_LOGS option to erase DVR logs after operations complete. This makes it both an information disclosure and account-manipulation tool. Structurally, the file defines a MetasploitModule class inheriting from Msf::Auxiliary and includes Remote::Tcp, Scanner, and Report mixins. It registers user-configurable options such as USERNAME, PASSWORD, TIMEOUT, HTTP_FALLBACK, HTTP_PORT, HTTP_SSL, and RPORT. The code contains hardcoded binary request constants for Dahua protocol operations and helper/reporting methods for storing recovered credentials associated with DDNS, SMTP/email, NAS/FTP, and HTTP services. The presence of reporting helpers indicates the module is designed for operational scanning and credential harvesting within the Metasploit ecosystem. Fingerprintable targets and endpoints include TCP port 37777 for the Dahua binary service, optional HTTP port 80 and HTTPS port 443, and unauthenticated CGI paths /cgi-bin/userManager.cgi?action=getUserInfoAll and /cgi-bin/configManager.cgi?action=getConfig&name=General. The module also uses Dahua-specific HTTP signatures such as Dahua-Webs, DHttp, DH_WEB, webLogin, and a JSON "session" field to identify compatible web interfaces. Overall, this is a mature, framework-integrated exploit/scanner module intended to find vulnerable Dahua DVRs, extract configuration and credentials, and optionally alter device state by resetting passwords and clearing logs.
This repository contains a single Metasploit auxiliary scanner module targeting Dahua-based DVRs vulnerable to CVE-2013-6117 (authentication bypass). The module communicates with the DVR over TCP (default port 37777) using custom binary protocol payloads. It can extract a wide range of sensitive information, including user hashes, email and DDNS settings, NAS configuration, channel assignments, group information, and the device serial number. Additionally, it can reset the password of a specified user and clear the device logs, potentially covering tracks after exploitation. The module is operational and provides real attack capabilities, but does not provide a shell or arbitrary code execution. The exploit is highly fingerprintable by its use of the Dahua DVR management protocol on port 37777. The code is well-structured, with clear separation of actions and reporting of discovered credentials to the Metasploit database.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.