CVE-2025-31702 is an authenticated privilege-escalation vulnerability in certain Dahua embedded products. An attacker holding valid normal-user credentials can submit a specific HTTP request to access data restricted to administrators, including system-sensitive files. Access to this data can enable tampering with the administrator password and escalation from a normal-user account to administrative privileges. The issue is a post-authentication flaw and does not describe Dahua P2P relay abuse or an unauthenticated access method.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository provides research tools and proof-of-concept scripts related to CVE-2025-31702, a vulnerability affecting Dahua P2P/Easy4IP-enabled devices. The repository contains three main Python scripts: 1. 'dahua-ac1secedata2.py': Decrypts Dahua device data blobs (Account1SecEData) using a derived key from device class and serial number, extracting sensitive information such as JSON configuration or credentials. 2. 'dahua-generatecode2.py': Generates authentication codes for Dahua devices by replicating the device's code generation logic, using device serial, timestamp, email, and other parameters. 3. 'dahua-sn-brute2.py': Brute-forces valid Dahua device serial numbers by generating candidate serials and probing the Dahua P2P/Easy4IP cloud infrastructure (www.easy4ipcloud.com:8800) via UDP/HTTP requests. Valid serials are saved to 'valid_serials.txt'. The repository is structured for defensive and research use, with a focus on detection, validation, and incident response. The scripts require Python 3.10+ and interact with Dahua's cloud endpoints, making them suitable for both vulnerability research and blue team validation. No weaponized payloads are present; the code is primarily for proof-of-concept and research purposes.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unrelated CVE identifier used as a label in recovered campaign tooling; the content does not establish that this vulnerability was exploited in the campaign.
A CVE identifier present only as an incorrect or unrelated toolkit/directory label; the content does not attribute the campaign's Dahua camera compromise technique to this vulnerability.
A CVE identifier incorrectly applied within the operator's toolkit to a technique it does not describe; the content provides no valid vulnerability details or confirmed relationship to the camera compromises.
A vulnerability reference found in the toolkit but explicitly not exploited in the observed CameraSwarm attacks.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.