Exploitation Summary
EIP tracks 1 public exploit for CVE-2021-33543.
PoCs published by Titouan Lazard, Ibrahim Ayadhi, Sébastien Charbonnier, including Metasploit module exploits/linux/http/geutebruck_cmdinject_cve_2021_335xx.
AI-analyzed exploit summary This Metasploit module exploits multiple authenticated command injection vulnerabilities in Geutebruck devices by bypassing HTTP basic authentication and injecting commands via various CGI parameters. It supports multiple CVEs and achieves remote code execution as root.
Description
Multiple camera devices by UDP Technology, Geutebrück and other vendors allow unauthenticated remote access to sensitive files due to default user authentication settings. This can lead to manipulation of the device and denial of service.
Exploits (1)
This Metasploit module exploits multiple authenticated command injection vulnerabilities in Geutebruck devices by bypassing HTTP basic authentication and injecting commands via various CGI parameters. It supports multiple CVEs and achieves remote code execution as root.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H