# CVE-2026-29114

## Summary

- **CVE ID:** CVE-2026-29114
- **Severity:** LOW
- **CVSS Score:** 2.3 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-538
- **Published:** Jun 10, 2026
- **Last Modified:** Jun 10, 2026

## Description

A vulnerability has been found in some Dahua products. An attacker
may obtain the device’s CA root certificate. If that CA is installed and
trusted on client systems, the attacker could issue fraudulent certificates
trusted by those clients and undermine the certificate trust chain.

## Affected Products

- Dahua — IPC (Some IPC models are affected, specifically those with a build date before April 15, 2026.)

## References

- [CNA](https://www.dahuasecurity.com/about-dahua/trust-center/dahua-psirt/dhcc-sa-202606-001:-security-advisory-%E2%80%93-vulnerabilities-found-in-some-dahua-products)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.19%
- **EPSS Percentile:** 8.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._