nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-34059 CVE-2025-34059
HIGH
Dahua Smart Cloud Gateway Registration Management Platform SQL Injection
Record summary
CVE-2025-34059 has a selected CVSS score of 8.7 (high).
Description
An SQL injection vulnerability exists in the Dahua Smart Cloud Gateway Registration Management Platform via the username parameter in the /index.php/User/doLogin endpoint. The application fails to properly sanitize user input, allowing unauthenticated attackers to inject arbitrary SQL statements and potentially disclose sensitive information. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 1, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 1, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Smart Cloud Gateway Registration Management PlatformBrowse Dahua / Smart Cloud Gateway Registration Management Platform | VulnCheck | Version data not supplied | |
Smart Cloud Gateway Registration Management PlatformBrowse Zhejiang Dahua Technology Co., Ltd. / Smart Cloud Gateway Registration Management PlatformDefault status: unknown | CVE List | Version range not supplied | affected |
References
6pentest-tools.comThird-party advisory
https://pentest-tools.com/vulnerabilities-exploits/zhejiang-dahua-smart-cloud-gateway-registration-platform-sql-injection-cnvd-2024-38747_23762 vulncheck.comThird-party advisory
https://vulncheck.com/advisories/dahua-smart-cloud-gateway-sql-injection cnblogs.comexploit
https://www.cnblogs.com/LeouMaster/p/18509644 cnvd.org.cnThird-party advisory
https://www.cnvd.org.cn/flaw/show/CNVD-2024-38747 dahuatech.comproduct
https://www.dahuatech.com/