Vulnerability record · CVE-2017-6343 · published 27 February 2017
CVE-2017-6343: Dahua NVR and camera web interface authentication bypass via MD5 admin hash
Dahuasecurity · Camera Firmware
The web interface on Dahua DHI-HCVR7216A-S3 devices (NVR Firmware 3.210.0001.10, Camera Firmware 2.400.0000.28.R, SmartPSS 1.16.1) allows remote attackers to gain login access by knowing the MD5 Admin Hash without knowing the corresponding password. This is an improper authentication flaw (CWE-287) distinct from CVE-2013-6117, and it matters because the hash is often exposed or recoverable, turning it into a credential-equivalent secret for the device web UI.
Description
The web interface on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 allows remote attackers to obtain login access by leveraging knowledge of the MD5 Admin Hash without knowledge of the corresponding password, a different vulnerability than CVE-2013-6117.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 3.0 base score is 8.1 (HIGH) with network reachability and no authentication or user interaction, and EPSS is 0.60349 at the 99.1st percentile, though the record does not confirm active exploitation or KEV listing.
What it is
The web interface on Dahua DHI-HCVR7216A-S3 devices (NVR Firmware 3.210.0001.10, Camera Firmware 2.400.0000.28.R, SmartPSS 1.16.1) allows remote attackers to gain login access by knowing the MD5 Admin Hash without knowing the corresponding password. This is an improper authentication flaw (CWE-287) distinct from CVE-2013-6117, and it matters because the hash is often exposed or recoverable, turning it into a credential-equivalent secret for the device web UI.
Impact
An attacker who obtains the MD5 admin hash can log in as administrator without cracking the password, gaining full control of the NVR, camera and SmartPSS management interface. That access can expose live video, recordings and device configuration, and may allow further lateral movement on the surveillance network.
Attack surface
Reached over the network through the device web interface (CVSS AV:N, PR:N, UI:N), so no authentication and no user interaction are required once the attacker has the MD5 admin hash. The record does not state how the hash is obtained, so that precondition must be treated as an external dependency.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is 0.60349 (99.1st percentile), indicating a high modeled likelihood of exploitation. References are third-party advisories and a VDB entry only; no public exploit code is cited in the record.
What to do
- Apply the vendor firmware/software updates for the affected NVR, camera and SmartPSS versions; the record does not list fixed versions, so confirm with Dahua support.
- Do not expose the device web interface to the internet; restrict management access to a trusted VLAN or VPN.
- Change admin credentials and rotate any shared or default passwords, and treat the MD5 admin hash as a secret that must not be disclosed.
- Disable or restrict SmartPSS remote management where it is not required, and audit accounts that can reach the web UI.
- Monitor vendor advisories for this CVE and for related Dahua authentication issues such as CVE-2013-6117.
Detection
- Review web server and device logs for successful admin logins that do not correlate with a normal password-authentication event or expected source IP.
- Alert on authentication attempts or sessions originating from unexpected external or non-management-network addresses to the NVR/camera web interface.
- Hunt for known Dahua web interface paths and hash-related request patterns in network or proxy logs.
- Inventory internet-exposed Dahua NVR, camera and SmartPSS instances and flag any that are reachable from untrusted networks.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/96449 | Third Party AdvisoryVDB Entry |
| https://nullku7.github.io/stuff/exposure/dahua/2017/02/24/dahua-nvr.html | Third Party Advisory |
| http://www.securityfocus.com/bid/96449 | Third Party AdvisoryVDB Entry |
| https://nullku7.github.io/stuff/exposure/dahua/2017/02/24/dahua-nvr.html | Third Party Advisory |
Track CVE-2017-6343 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-6343), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.