This Python script demonstrates an authentication bypass vulnerability in Dahua DVR/NVR/IPC devices by exploiting undocumented direct file access to download user credentials and log in without valid authentication. It supports both Generation 2 and 3 devices with different hash processing methods.
Classification
Working Poc 95%
Target:
Dahua DVR/NVR/IPC devices (multiple versions)
No auth needed
Prerequisites:
Network access to the target device · HTTP/HTTPS access to the device's web interface