CVE-2013-3615

Dahua DVR - Weak Password Hash Vulnerability

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-3615.

AI-analyzed exploit summary The provided code is a Metasploit module that exploits an authentication bypass vulnerability in Dahua DVR devices (CVE-2013-6117). It demonstrates the ability to interact with the administrative service on TCP port 37777 without authentication, allowing unauthorized access to sensitive information and actions such as password resets and log clearing.

Description

Dahua DVR appliances use a password-hash algorithm with a short hash length, which makes it easier for context-dependent attackers to discover cleartext passwords via a brute-force attack.

Exploits (1)

exploitdb WORKING POC
webappshardware
https://www.exploit-db.com/exploits/29673

The provided code is a Metasploit module that exploits an authentication bypass vulnerability in Dahua DVR devices (CVE-2013-6117). It demonstrates the ability to interact with the administrative service on TCP port 37777 without authentication, allowing unauthorized access to sensitive information and actions such as password resets and log clearing.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Dahua web-enabled DVRs (v2.608.0000.0 and 2.608.GV00.0)
No auth needed
Prerequisites: Network access to the target device on TCP port 37777
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (1)

Core 1
Core References
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/800094

Scores

EPSS 0.0766
EPSS Percentile 93.8%

Details

CWE
CWE-255
Status published
Products (50)
dahuasecurity/dvr0404hd-a
dahuasecurity/dvr0404hd-l
dahuasecurity/dvr0404hd-s
dahuasecurity/dvr0404hd-u
dahuasecurity/dvr0404hf-a-e
dahuasecurity/dvr0404hf-al-e
dahuasecurity/dvr0404hf-s-e
dahuasecurity/dvr0404hf-u-e
dahuasecurity/dvr0804
dahuasecurity/dvr0804hd-l
... and 40 more
Published Sep 17, 2013
Tracked Since Feb 18, 2026