Record summary

CVE-2025-34059 has a selected CVSS score of 8.7 (high).

Description

An SQL injection vulnerability exists in the Dahua Smart Cloud Gateway Registration Management Platform via the username parameter in the /index.php/User/doLogin endpoint. The application fails to properly sanitize user input, allowing unauthenticated attackers to inject arbitrary SQL statements and potentially disclose sensitive information. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jul 1, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 1, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Smart Cloud Gateway Registration Management Platform

Browse Dahua / Smart Cloud Gateway Registration Management Platform
VulnCheckVersion data not supplied

Default status: unknown

CVE ListVersion range not suppliedaffected

References

6