Umair Aziz

2 exploits Active since Sep 2021
CVE-2021-33044 NOMISEC CRITICAL WORKING POC
Dahua IPC-HUM7XXX IPC-HX3XXX IPC-HX5XXX SD1A1 SD22 SD49 SD50 SD52C SD6AL TPC-BF1241 Firmware Authentication Bypass
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
2 stars
CVSS 9.8
CVE-2025-31700 NOMISEC HIGH WORKING POC
Dahua IPC and SD Series - Buffer Overflow via Malicious Packet
A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending specially crafted malicious packets, potentially causing service disruption (e.g., crashes) or remote code execution (RCE). Some devices may have deployed protection mechanisms such as Address Space Layout Randomization (ASLR), which reduces the likelihood of successful RCE exploitation. However, denial-of-service (DoS) attacks remain a concern.
2 stars
CVSS 8.1