CVE-2021-33044
CRITICAL KEV NUCLEIDahua - Auth Bypass
Title source: llmDescription
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
Exploits (8)
nomisec
WORKING POC
2 stars
by umair-aziz025 · poc
https://github.com/umair-aziz025/dahua-cve-research
nomisec
WORKING POC
by eagle-nett · infoleak
https://github.com/eagle-nett/DAHUA_AUTH-BYPASS-CVE-2021-33044
Nuclei Templates (1)
Dahua IPC/VTH/VTO - Authentication Bypass
CRITICALby gy741
References (4)
Scores
CVSS v3
9.8
EPSS
0.9425
EPSS Percentile
99.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2024-08-21
VulnCheck KEV
2023-12-05
InTheWild.io
2024-08-21
ENISA EUVD
EUVD-2021-19759
CWE
CWE-287
Status
published
Products (19)
dahuasecurity/ipc-hum7xxx_firmware
< 2.820.0000000.5.r.210705
dahuasecurity/ipc-hx3xxx_firmware
< 2.800.0000000.29.r.210630
dahuasecurity/ipc-hx5xxx_firmware
< 2.820.0000000.18.r.210705
dahuasecurity/sd1a1_firmware
< 2.812.0000007.0.r.210706
dahuasecurity/sd22_firmware
< 2.812.0000007.0.r.210706
dahuasecurity/sd49_firmware
< 2.812.0000007.0.r.210706
dahuasecurity/sd50_firmware
< 2.812.0000007.0.r.210706
dahuasecurity/sd52c_firmware
< 2.812.0000007.0.r.210706
dahuasecurity/sd6al_firmware
< 2.812.0000007.0.r.210706
dahuasecurity/tpc-bf1241_firmware
< 2.630.0000000.6.r.210707
... and 9 more
Published
Sep 15, 2021
KEV Added
Aug 21, 2024
Tracked Since
Feb 18, 2026