CVE-2025-8773

HIGH

DahuaTech Monitoring Platform 1.0 - SQL Injection via userBean.loginName Parameter

Title source: llm
STIX 2.1

Description

A vulnerability, which was classified as critical, was found in Dinstar Monitoring Platform 甘肃省危险品库监控平台 1.0. Affected is an unknown function of the file /itc/$%7BappPath%7D/login_getPasswordErrorNum.action. The manipulation of the argument userBean.loginName leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.319296
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.319296
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.625361

Scores

CVSS v3 7.3
EPSS 0.0056
EPSS Percentile 42.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-74 CWE-89
Status published
Products (1)
dahuatech/monitoring_platform 1.0
Published Aug 09, 2025
Tracked Since Feb 18, 2026