Critical Alert 1 Active Exploit Detected Today

CVE-2026-60004 Gitea Code Injection Vulnerability →
Powered by CVE Watchtower
×
August 26, 2026

CVE Watchtower


← Back to CVE List

CVE-2025-31702NVD

Vulnerability Summary

A vulnerability exists in certain Dahua embedded products. Third-party malicious attacker with obtained normal user credentials could exploit the vulnerability to access certain data which are restricted to admin privileges, such as system-sensitive files through specific HTTP request. This may cause tampering with admin password, leading to privilege escalation. Systems with only admin account are not affected.
Severity Level
MEDIUM(6.8)
Published Date
Oct 15, 2025
Last Modified
Oct 15, 2025
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
Data Pending
Root Weakness (CWE)
Refer to the official MITRE database for detailed architectural specifications regarding this weakness.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityNone