Junglewise Threat Intelligence

CVE-2021-33044: Dahua IP Camera Authentication Bypass Vulnerability

CVE-2021-33044 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-08-21

Vendors: Dahua.

Executive brief

Dahua IP cameras and related products contain an authentication bypass vulnerability during the login process. Attackers can bypass device identity authentication by constructing malicious data packets, specifically when the NetKeyboard type argument is specified by the client.

Affected products

  • Dahua SD41 firmware up to (excluding) 2.812.0000007.0.r.210706
  • Dahua SD49 firmware up to (excluding) 2.812.0000007.0.r.210706
  • Dahua IPC-HUM7XXX firmware up to (excluding) 2.820.0000000.5.r.210705
  • Dahua IPC-HX3XXX firmware up to (excluding) 2.800.0000000.29.r.210630
  • Dahua IPC-HX5XXX firmware up to (excluding) 2.820.0000000.18.r.210705

Timeline

  • 2021-09-30: disclosed: Initial analysis by NIST
  • 2024-08-21: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-08-21: exploited: Reported as exploited in the wild in CISA KEV catalog

Related threats