{"advisories":[{"id":"EUVD-2024-54921","source":"euvd","title":"A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to execute arbitrary system commands via the capture_handle.action interface. The flaw stems from improper input validation in the captureCommand parameter, which is processed without sanitization or authentication. By sending crafted HTTP requests, attackers can inject OS-level commands that are executed on the server, leading to full system compromise. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-04-06 UTC.","url":"https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-54921"}],"cve":"CVE-2024-13985","epss":{"score":0.15095},"mitre":{"cpes":[],"created":"2025-08-27T21:23:37.944000+00:00","description":"A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to execute arbitrary system commands via the capture_handle.action interface. The flaw stems from improper input validation in the captureCommand parameter, which is processed without sanitization or authentication. By sending crafted HTTP requests, attackers can inject OS-level commands that are executed on the server, leading to full system compromise. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-04-06 UTC.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{"score":10,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}},"mitre_repo_path":"cves/2024/13xxx/CVE-2024-13985.json","references":["https://blog.csdn.net/weixin_43567873/article/details/136636198","https://cn-sec.com/archives/2554372.html","https://github.com/ahisec/nuclei-tps/blob/main/http/vulnerabilities/dahua/dahua-eims-capture-handle-rce.yaml","https://pentest-tools.com/vulnerabilities-exploits/dahua-eims-remote-command-execution_23961","https://s4e.io/tools/dahua-eims-remote-code-execution","https://support.dahuatech.com/bulletin/info?IsDpValue=APKncD%2FBd6zIq4O2BUpuhjg6hGbLYAQKuf5hnmPaK9M%3D","https://www.cnvd.org.cn/flaw/show/CNVD-2024-17054","https://www.vulncheck.com/advisories/dahua-eims-rce"],"title":"Dahua EIMS capture_handle.action RCE","updated":"2026-05-15T11:14:33.939000+00:00","vendors":[],"weaknesses":["CWE-78"]},"nvd":{"cpes":[],"created":"2025-08-27T22:15:33.960000+00:00","description":"A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to execute arbitrary system commands via the capture_handle.action interface. The flaw stems from improper input validation in the captureCommand parameter, which is processed without sanitization or authentication. By sending crafted HTTP requests, attackers can inject OS-level commands that are executed on the server, leading to full system compromise. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-04-06 UTC.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{"score":10.0,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}},"nvd_repo_path":"2024/CVE-2024-13985.json","references":["https://blog.csdn.net/weixin_43567873/article/details/136636198","https://cn-sec.com/archives/2554372.html","https://github.com/ahisec/nuclei-tps/blob/main/http/vulnerabilities/dahua/dahua-eims-capture-handle-rce.yaml","https://pentest-tools.com/vulnerabilities-exploits/dahua-eims-remote-command-execution_23961","https://s4e.io/tools/dahua-eims-remote-code-execution","https://support.dahuatech.com/bulletin/info?IsDpValue=APKncD%2FBd6zIq4O2BUpuhjg6hGbLYAQKuf5hnmPaK9M%3D","https://www.cnvd.org.cn/flaw/show/CNVD-2024-17054","https://www.vulncheck.com/advisories/dahua-eims-rce"],"title":null,"updated":"2026-06-17T07:03:06.597000+00:00","vendors":[],"weaknesses":["CWE-78"]},"opencve":{"changes":[{"created":"2025-08-27T21:30:00+00:00","data":[{"details":{"new":"A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to execute arbitrary system commands via the capture_handle.action interface. The flaw stems from improper input validation in the captureCommand parameter, which is processed without sanitization or authentication. By sending crafted HTTP requests, attackers can inject OS-level commands that are executed on the server, leading to full system compromise.","old":null},"type":"description"},{"details":{"new":"Dahua EIMS capture_handle.action RCE","old":null},"type":"title"},{"details":{"added":["CWE-78"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://blog.csdn.net/weixin_43567873/article/details/136636198","https://cn-sec.com/archives/2554372.html","https://github.com/ahisec/nuclei-tps/blob/main/http/vulnerabilities/dahua/dahua-eims-capture-handle-rce.yaml","https://pentest-tools.com/vulnerabilities-exploits/dahua-eims-remote-command-execution_23961","https://s4e.io/tools/dahua-eims-remote-code-execution","https://support.dahuatech.com/bulletin/info?IsDpValue=APKncD%2FBd6zIq4O2BUpuhjg6hGbLYAQKuf5hnmPaK9M%3D","https://www.cnvd.org.cn/flaw/show/CNVD-2024-17054","https://www.vulncheck.com/advisories/dahua-eims-rce"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV4_0":{"score":10,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"3cde18a4-460e-4372-8c7f-2bc1eb246fc6"},{"created":"2025-08-28T14:15:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"01c408ca-dc35-4693-b994-a609ce7ad203"},{"created":"2025-08-28T20:00:00+00:00","data":[{"details":{"new":"A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to execute arbitrary system commands via the capture_handle.action interface. The flaw stems from improper input validation in the captureCommand parameter, which is processed without sanitization or authentication. By sending crafted HTTP requests, attackers can inject OS-level commands that are executed on the server, leading to full system compromise. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-04-06 UTC.","old":"A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to execute arbitrary system commands via the capture_handle.action interface. The flaw stems from improper input validation in the captureCommand parameter, which is processed without sanitization or authentication. By sending crafted HTTP requests, attackers can inject OS-level commands that are executed on the server, leading to full system compromise."},"type":"description"}],"id":"9f2220d4-8497-4973-83ad-dd1207a53023"}],"cpes":{"data":[],"providers":[]},"created":{"data":"2025-08-27T21:23:37.944000+00:00","provider":"mitre"},"description":{"data":"A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to execute arbitrary system commands via the capture_handle.action interface. The flaw stems from improper input validation in the captureCommand parameter, which is processed without sanitization or authentication. By sending crafted HTTP requests, attackers can inject OS-level commands that are executed on the server, leading to full system compromise. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-04-06 UTC.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{},"provider":null},"cvssV4_0":{"data":{"score":10,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"},"provider":"mitre"},"epss":{"data":{"score":0.15095},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://blog.csdn.net/weixin_43567873/article/details/136636198","https://cn-sec.com/archives/2554372.html","https://github.com/ahisec/nuclei-tps/blob/main/http/vulnerabilities/dahua/dahua-eims-capture-handle-rce.yaml","https://pentest-tools.com/vulnerabilities-exploits/dahua-eims-remote-command-execution_23961","https://s4e.io/tools/dahua-eims-remote-code-execution","https://support.dahuatech.com/bulletin/info?IsDpValue=APKncD%2FBd6zIq4O2BUpuhjg6hGbLYAQKuf5hnmPaK9M%3D","https://www.cnvd.org.cn/flaw/show/CNVD-2024-17054","https://www.vulncheck.com/advisories/dahua-eims-rce"],"providers":["mitre","nvd"]},"title":{"data":"Dahua EIMS capture_handle.action RCE","provider":"mitre"},"updated":{"data":"2026-04-15T00:35:42.020000+00:00","provider":"nvd"},"vendors":{"data":[],"providers":[]},"weaknesses":{"data":["CWE-78"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2025-08-27T21:23:37.944000+00:00","description":"A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to execute arbitrary system commands via the capture_handle.action interface. The flaw stems from improper input validation in the captureCommand parameter, which is processed without sanitization or authentication. By sending crafted HTTP requests, attackers can inject OS-level commands that are executed on the server, leading to full system compromise. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-04-06 UTC.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":"Dahua EIMS capture_handle.action RCE","updated":"2025-08-28T13:59:45.571000+00:00","vendors":[],"vulnrichment_repo_path":"2024/13xxx/CVE-2024-13985.json","weaknesses":[]}}