CVE-2026-29114
LOWDahua Ipc - Insertion of Sensitive Information into Externally-Accessible File or Directory
Title source: ruleExploitation Summary
EIP tracks 1 public exploit for CVE-2026-29114. PoCs published by CrimsonfiedOfficial.
AI-analyzed exploit summary Detailed technical analysis of CVE-2026-29114, a low-severity certificate-trust vulnerability in Dahua IPC models where the device's internal CA root certificate can be remotely obtained. The writeup covers root cause (CWE-538), attack prerequisites, CVSS scoring, and mitigation steps, emphasizing PKI trust abuse risks if the CA is trusted on client systems.
Description
A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that CA is installed and trusted on client systems, the attacker could issue fraudulent certificates trusted by those clients and undermine the certificate trust chain.
Exploits (1)
Detailed technical analysis of CVE-2026-29114, a low-severity certificate-trust vulnerability in Dahua IPC models where the device's internal CA root certificate can be remotely obtained. The writeup covers root cause (CWE-538), attack prerequisites, CVSS scoring, and mitigation steps, emphasizing PKI trust abuse risks if the CA is trusted on client systems.
Scores
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X