CVE-2021-33044

CRITICAL KEV NUCLEI

Dahua - Auth Bypass

Title source: llm

Description

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

Exploits (8)

nomisec WORKING POC 176 stars
by bp2008 · poc
https://github.com/bp2008/DahuaLoginBypass
nomisec WORKING POC 2 stars
by umair-aziz025 · poc
https://github.com/umair-aziz025/dahua-cve-research
nomisec WORKING POC 2 stars
by haingn · remote
https://github.com/haingn/LoHongCam-CVE-2021-33044
nomisec WORKING POC 1 stars
by Spy0x7 · poc
https://github.com/Spy0x7/CVE-2021-33044
nomisec WORKING POC
by Bd-Mutant7 · poc
https://github.com/Bd-Mutant7/DahuaLoginBypass
nomisec WORKING POC
by eagle-nett · infoleak
https://github.com/eagle-nett/DAHUA_AUTH-BYPASS-CVE-2021-33044
nomisec WORKING POC
by Baza-NATO · remote-auth
https://github.com/Baza-NATO/CVE-2021-33044

Nuclei Templates (1)

Dahua IPC/VTH/VTO - Authentication Bypass
CRITICALby gy741

Scores

CVSS v3 9.8
EPSS 0.9425
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2024-08-21
VulnCheck KEV 2023-12-05
InTheWild.io 2024-08-21
ENISA EUVD EUVD-2021-19759
CWE
CWE-287
Status published
Products (19)
dahuasecurity/ipc-hum7xxx_firmware < 2.820.0000000.5.r.210705
dahuasecurity/ipc-hx3xxx_firmware < 2.800.0000000.29.r.210630
dahuasecurity/ipc-hx5xxx_firmware < 2.820.0000000.18.r.210705
dahuasecurity/sd1a1_firmware < 2.812.0000007.0.r.210706
dahuasecurity/sd22_firmware < 2.812.0000007.0.r.210706
dahuasecurity/sd49_firmware < 2.812.0000007.0.r.210706
dahuasecurity/sd50_firmware < 2.812.0000007.0.r.210706
dahuasecurity/sd52c_firmware < 2.812.0000007.0.r.210706
dahuasecurity/sd6al_firmware < 2.812.0000007.0.r.210706
dahuasecurity/tpc-bf1241_firmware < 2.630.0000000.6.r.210707
... and 9 more
Published Sep 15, 2021
KEV Added Aug 21, 2024
Tracked Since Feb 18, 2026