CVE-2024-13985
Executive Summary
A command injection flaw in Dahua EIMS (versions <2240008) allows unauthenticated attackers to execute arbitrary OS commands via the capture_handle.action interface. The vulnerability arises from unsanitized captureCommand input, enabling full system compromise when crafted HTTP requests are sent. Shadowserver Foundation first observed exploitation on 2024-04-06 UTC. The issue is not yet listed in CISA KEV.
Authoritative CVE Metadata - CVSS Base Score: Unknown (Unknown) - Published: 2025-08-27T22:15:33.960 - Last Modified: 2026-09-26T21:10:00.130
Original Description: A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to execute arbitrary system commands via the capture_handle.action interface. The flaw stems from improper input validation in the captureCommand parameter, which is processed without sanitization or authentication. By sending crafted HTTP requests, attackers can inject OS-level commands that are executed on the server, leading to full system compromise. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-04-06 UTC.
"A man is not where he lives but where he loves."
— Unknown