What is CVE-2025-31702?
A critical authentication bypass vulnerability exploited in the Operation CameraSwarm campaign targeting Dahua cameras. Attackers leveraged this flaw alongside P2P relay abuse to compromise over 14,000 devices across Ukraine and Russia for botnet operations. Affected users must immediately apply firmware updates and restrict network-level access to mitigate the threat.
Azərbaycanca: Operation CameraSwarm kampaniyası çərçivəsində kibercinayətkarlar tərəfindən Dahua kameralarını hədəf almaq üçün istifadə edilən kritik autentifikasiyadan yan keçmə (auth-bypass) zəifliyidir. Bu zəiflikdən uğurla istifadə edən təcavüzkarlar Ukrayna və Rusiya üzrə 14,000-dən çox kameranı ələ keçirərək onları böyük bir botnet şəbəkəsinə çeviriblər. Təsirə məruz qalan sistemlərin administratorları dərhal cihaz proqram təminatını yeniləməli və şəbəkə səviyyəsində məhdudiyyətlər tətbiq etməlidirlər.
Related CVEs
link basis: same weakness class CWE-287; shared vendor: Dahua
FAQ1
What type of vulnerability is CVE-2025-31702 and how was it exploited in Operation CameraSwarm?
CVE-2025-31702 is a critical authentication bypass vulnerability targeting Dahua cameras. As part of the Operation CameraSwarm campaign, cybercriminals exploited this flaw alongside P2P relay abuse to compromise over 14,000 devices across Ukraine and Russia, converting them into a large botnet.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.