The tool that Dahua claims will alert users if Dahua's firmware is out-of-date does not work if the firmware is actually out-of-date, per a declaration that Dahua provided to IPVM after we reported on Dahua's newest critical vulnerabilities and the fact that their firmware checker did not work on out-of-date firmware we tested.
Inside this note, we share Dahua's explanation, our test findings, and why this increases risks for Dahua users already beset by vulnerability after vulnerability.
IPVM conducts reporting, tutorials and software funded by subscriber's payments enabling us to offer the most independent, accurate and in-depth information.
Comments (5)
Undisclosed Integrator #1
*** ********* ******** ********?
Create New Topic
Undisclosed #2
***** ****’** ****** **** **’* ***** in *** *** ******** **** *** wouldn’t **** ******?
Create New Topic
Undisclosed Integrator #3
**** ********** ** ***** *** ******** tech ******* ** *** *******. ***** should **** ****** ************ *** *******, explained **** ***** ******** *** ** issue **** ***** **** ** ****** the ******* ******** ****** ******** ******* had **** **** ******** ** ********, sent ** ****** *** **** ***** restore *** ****** ** ****** ********* and ***** *** ****** ****** ******* to **** ** ** ****** ***** forward. ******* ******.
*** ****** ******* ** ****: *****, it *** **** *** ********** **** all ******** ********, *********, *** ********, that ** * ******* ******** ******** update ******** ********* ******* *** ******* version, **** ********* *** ******** ** with *** **** ****** ******* ******** or *************. ******* ******. ** ******** uses ** ******** * ****** ** incremental ******* ** ***** ** **** properly, **** ** *** ** ********* detect *** **** *********** ****/******* ***** to ******* **** *** **** *********** update. ** ** ****** ** ****, then ** *** ****** **** *********** and ******* * **** ******** *********** as ** ****** ** ****** **** happened ** *** **** **** **** not ******. ** ** *** ****** incremental ******* *** *** * **** practice, **** ** **** ******* **** time ** ******** *** *********. ***** incremental ******* ***** ******** ******** ** be ******* ** * ****** *******, historically ** ** *** ******* *** new ******* ** ********* ********* ********/****** that *** *** ***** ******.
***** *** ******* ******** ** * product ** ** ********* ** **** it ** ******** ** **, * good ****** *** *********** ***** ** to *** *** **** *** *** versions ** ****** ********* *** ****** operation, ***** ** ******* ** *** to * ******** **** ***** ******* are ********* ******* ******* ********. ** an ****** **** ****** *** ******, it *** ** ********** ****** *** customers ** *** **** ****, ******** a ******* *********. ** *** ****** is ******** *******, **** ************ ****** be **** ** **********/******* ** *** user ** ******** ** ** ********* that *** ****** ** *******, ** they *** ****** *** **** ******** individually *** **** ****** ** **************.
****** **** ** **** ** **** for ******** *******, **** ** ******** and ********* ** *** ***** ********* updating ** **** *****, *** ******* firmware ** ******* ************ ***** ******** a **** ****** ******* ** *********** approach. *** * ****** ** ** automatic ******* ******** ** ** ‘***** in’ **** * ****** ********* ** download *** ****** ********. **** *** it’s *** ******** ***** ** ****** update ******* *** ** ******* ******** updates ** ** ********** **** *** wrong ******, *** ******* ** ******, download ******* ** ***** ******* ********. This ****** *** **** **** ** the **** ** ************ ***** ******** to *********** *** **** **** ********.
*** ‘***** **’ ******* ** **** one ** *** **** ******* ******* have ***** ** ** *** ***** in *** **** *** *****. ** enabling **, ******* *** ******* ** reach *** *** ***** ******* **** once ********* *** ** **** ** do ****** ***** **** ****** ********. For *******, ******* ****** ******, ******* status, *********** ***** ******* ** *******, and/or ******* ********** **** ** *******. It ***** * **** **** ***** be ********* ***** ** *** *********** managing *** ****** **** *** **********. IT ***** * **** ** ******** network ** ***** **** ****** ****. Generally **** ******** **** *** ** detected ******* ******** ********** ******** ******* on ******* ********** *** *******. ********* and ***** ******** ********** ******* **** many **** ** ******* ******* ***** products, *** ******** ***** ***** ******* tend ** ******* ** ***** ***, and ***** ********* ***** **** *** ones ******** *** ***** ****** *******, are ********* ** ******.
** *** ****** *** ** ******** might **** ** ** ****** ***** auto ******* ** ** ******* ** embedded ******** ** **** ** *** allowing *** ***** ******** ** ** installed ** ***** **** ** **** networks. ******* ***** ******* ****** *** entirely ** ***** *** *******, **** their *** ******** ******** ******* ** portal, **** ** *** ** ********* thing ** **, *** ******** ***** isolation ** *********** ***** ********.
************* ******* ******* **** ***** *********. They **** ** **** ** ******* and ************* **** **** ** ****** proper ********* *** ******* ******** ** all *********. ** **** **** ***’* of ************* ******** **** **** ***** and ** ***** ***** ** *** one **** *** *** ** **** time *** ****** **** ***** ******** or ********. ** *******.
*** **** ** ***** *** *** the **** *** **** ****** **** open *** ********** **** ******, *** quick ** ******* ****. **** ****** us ** ** *** **** *** our *******.
** * ************ ** *** ***** honest, ** ****** ******* ******* ** acknowledging ******** *** ********* *********, ** have ** **** ***** ****. ********* it *** **** ********* ***/** **** inconvenient ** **, *** ** **** it ** *** ***** ***** ** do *** *** ******* *** *** peace ** ****.
*** ****** **** *** ****** **** else *** **** *** ***** ****** about?
Create New Topic
Robert Shih
09/17/21 04:50pm
***! **'* **** ****** ***** *** one *** ** ******** ***** ******. Nothing *** ** *** ****.
****: * ******* **** **** **** kicking *** *** ** ** *** will ******** **** *** ******** *******. They **** ****** *** ******** ***** location **** **** **** ** ** one ************ ****** *** **** ** to *** ****. ****'* *** ******** beyond * *** ******. **** ***** to * ****** ********** ******** ******* location. **** *** ****** ****** ** them ****** "**'** **** **** ** it **** ****, ** *******". ** far, ** *** ******* **** **** issued **** *** ** ******** *** upgraded ** ***** ******** ** *** new ********.
**'* **** ** *** ****.
*** **** ********* ** **** ****-******* feature ** **** *********** ***** ******** firmware ************ ****** ***** ** ********* only ******** **** ******* ** **** who *** ***** ********* ********. *** upgrade ******* ***** **** ** ** stripped *** ** ******** ** ***** logo **** ***** "*******" ******** ***** for **** ** **** ***** ** they ******** **** ** ******* ***** OEMs ** *** ******* ******* **** firmware ***** *******.
Create New Topic