CVE-2021-33543

CRITICAL

Multiple Camera Devices - Info Disclosure

Title source: llm

Description

Multiple camera devices by UDP Technology, Geutebrück and other vendors allow unauthenticated remote access to sensitive files due to default user authentication settings. This can lead to manipulation of the device and denial of service.

Exploits (1)

metasploit WORKING POC EXCELLENT
by Titouan Lazard, Ibrahim Ayadhi, Sébastien Charbonnier · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/geutebruck_cmdinject_cve_2021_335xx.rb

Scores

CVSS v3 9.8
EPSS 0.8724
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-306
Status published
Products (48)
geutebrueck/g-cam_ebc-2110_firmware 1.12.13.2
geutebrueck/g-cam_ebc-2110_firmware 1.12.14.5
geutebrueck/g-cam_ebc-2110_firmware < 1.12.0.27
geutebrueck/g-cam_ebc-2111_firmware 1.12.13.2
geutebrueck/g-cam_ebc-2111_firmware 1.12.14.5
geutebrueck/g-cam_ebc-2111_firmware < 1.12.0.27
geutebrueck/g-cam_ebc-2112_firmware 1.12.13.2
geutebrueck/g-cam_ebc-2112_firmware 1.12.14.5
geutebrueck/g-cam_ebc-2112_firmware < 1.12.0.27
geutebrueck/g-cam_efd-2241_firmware 1.12.13.2
... and 38 more
Published Sep 13, 2021
Tracked Since Feb 18, 2026