CVE-2013-6117 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 69.7% (pctl 99)
Patch early
A public exploit exists.
Description
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and perform other actions via a request to TCP port 37777.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 69.68% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2014-07-11 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| dahuasecurity | dvr firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Dahua DVR 2.608.0000.0/2.608.GV00.0 - Authentication Bypass (Metasploit) | 2013-11-18 |
References
- http://blog.depthsecurity.com/2013/11/dahua-dvr-authentication-bypass-cve.html
- http://packetstormsecurity.com/files/124022/Dahua-DVR-Authentication-Bypass.html
- http://seclists.org/bugtraq/2013/Nov/62
- http://www.exploit-db.com/exploits/29673
- http://www.osvdb.org/99783
- http://blog.depthsecurity.com/2013/11/dahua-dvr-authentication-bypass-cve.html
- http://packetstormsecurity.com/files/124022/Dahua-DVR-Authentication-Bypass.html
- http://seclists.org/bugtraq/2013/Nov/62
- http://www.exploit-db.com/exploits/29673
- http://www.osvdb.org/99783
→ the Explorer · watch your stack · NVD