CameraRisk

CVE-2019-9676

Dahua

Published
12 June 2019
Last modified
17 June 2026
CVSS
7.8 v3.0
Severity
high
EPSS
0.4% (38th pct)
CISA KEV
Not listed
NVD status
Modified
Weaknesses
CWE-119

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

Buffer overflow vulnerability found in some Dahua IP Camera devices IPC-HFW1XXX,IPC-HDW1XXX,IPC-HFW2XXX Build before 2018/11. The vulnerability exits in the function of redirection display for serial port printing information, which can not be used by product basic functions. After an attacker logs in locally, this vulnerability can be exploited to cause device restart or arbitrary code execution. Dahua has identified the corresponding security problems in the static code auditing process, so it has gradually deleted this function, which is no longer available in the newer devices and softwares. Dahua has released versions of the affected products to fix the vulnerability.

Exploitation

Not listed in the CISA Known Exploited Vulnerabilities catalogue as of 2026.09.04. That is an absence of confirmed public exploitation, not evidence that exploitation has not occurred. EPSS models a 0.4% probability of exploitation activity in the next 30 days.

Affected products

ProductVendorTypeVersions named
Ipc-hdw1xxx Dahua IP camera < 2018-11
Ipc-hfw1xxx Dahua IP camera < 2018-11
Ipc-hfw2xxx Dahua IP camera < 2018-11

References

Vendor advisory and patch

CVE-2019-9676 at NVD

Record assembled from NVD, CISA KEV 2026.09.04 and FIRST EPSS 2026-09-04. Affected products are those NVD's CPE configuration names that fall inside this site's scope; a CVE may affect products outside it.