A vulnerability has been found in some Dahua products. An attacker
may obtain the device’s CA root certificate. If that CA is installed and
trusted on client systems, the attacker could issue fraudulent certificates
trusted by those clients and undermine the certificate trust chain.
Metrics
Affected Vendors & Products
References
History
Wed, 10 Jun 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Public Disclosure of Dahua IPC CA Root Certificate Enables Fake Trusted Certificates |
Wed, 10 Jun 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dahua
Dahua ipc |
|
| Vendors & Products |
Dahua
Dahua ipc |
Wed, 10 Jun 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that CA is installed and trusted on client systems, the attacker could issue fraudulent certificates trusted by those clients and undermine the certificate trust chain. | |
| Weaknesses | CWE-538 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: dahua
Published: 2026-06-10T05:44:50.397Z
Updated: 2026-06-10T05:44:50.397Z
Reserved: 2026-03-04T03:32:28.880Z
Link: CVE-2026-29114
No data.
Status : Received
Published: 2026-06-10T07:16:24.890
Modified: 2026-06-10T07:16:24.890
Link: CVE-2026-29114
No data.