← Vulnerability feed

Vulnerability record · CVE-2019-9682 · published 13 May 2020

CVE-2019-9682: Dahuasecurity sd6al firmware incorrect default permissions vulnerability

Dahuasecurity · Sd6al Firmware

Dahua devices with Build time before December 2019 use strong security login mode by default, but in order to be compatible with the normal login of early devices, some devices retain the weak security login mode that users can control. If the user uses a weak security login method, an attacker can monitor the device network to intercept network packets to attack the device. So it is recommended that the user disable this login method.

8.1 CVSS 3.1 High EPSS 0.86% · top 43.1% CWE-276 · Incorrect default permissions
8.1CVSS 3.1 base score, v2 6.8
0.86%EPSS exploitation probability, 30 days
NoNot in CISA KEV
20Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Dahua devices with Build time before December 2019 use strong security login mode by default, but in order to be compatible with the normal login of early devices, some devices retain the weak security login mode that users can control. If the user uses a weak security login method, an attacker can monitor the device network to intercept network packets to attack the device. So it is recommended that the user disable this login method.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

20 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-9682 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-33046Dahuasecurity ipc-hx1xxx firmware improper authentication vulnerabilitySome Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerability through specific deploy…EPSS 1.3%9.8CVE-2020-9502Dahuasecurity sd6al firmware vulnerabilitySome Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user access, an attacker can use …EPSS 1.5%7.2CVE-2020-9499Dahuasecurity sd6al firmware classic buffer overflow vulnerabilitySome Dahua products have buffer overflow vulnerabilities. After the successful login of the legal account, the attacker sends a specific DDNS test co…EPSS 1.5%4.9CVE-2020-9500Dahuasecurity sd6al firmware vulnerabilitySome products of Dahua have Denial of Service vulnerabilities. After the successful login of the legal account, the attacker sends a specific log que…EPSS 1.0%7.8CVE-2026-87886Acronis Backup plugins for cPanel, Plesk and DirectAdmin local privilege escalationAcronis Backup plugins for cPanel & WHM, Plesk and DirectAdmin on Linux ship with insecure file permissions (CWE-276), allowing a local user to escal…KEVEPSS 0.23%analysed6.5CVE-2022-22948VMware vCenter Server information disclosure via incorrect file permissionsvCenter Server ships files with incorrect default permissions, allowing a user with non-administrative access to read sensitive information. Because …KEVEPSS 13%analysed9.8CVE-2013-0632Adobe ColdFusion RDS default password authentication bypassAdobe ColdFusion 9.0 through 10 ships administrator.cfc with an RDS component that accepts a default empty password. An attacker can log in to RDS wi…KEVEPSS 94%analysed

Source: NIST National Vulnerability Database (record CVE-2019-9682), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.