CVE-2021-33543

CRITICAL

Multiple Camera Devices - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-33543. PoCs published by Titouan Lazard, Ibrahim Ayadhi, Sébastien Charbonnier, including Metasploit module exploits/linux/http/geutebruck_cmdinject_cve_2021_335xx.

AI-analyzed exploit summary This Metasploit module exploits multiple authenticated command injection vulnerabilities in Geutebruck devices by bypassing HTTP basic authentication and injecting commands via various CGI parameters. It supports multiple CVEs and achieves remote code execution as root.

Description

Multiple camera devices by UDP Technology, Geutebrück and other vendors allow unauthenticated remote access to sensitive files due to default user authentication settings. This can lead to manipulation of the device and denial of service.

Exploits (1)

metasploit WORKING POC EXCELLENT
by Titouan Lazard, Ibrahim Ayadhi, Sébastien Charbonnier · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/geutebruck_cmdinject_cve_2021_335xx.rb

This Metasploit module exploits multiple authenticated command injection vulnerabilities in Geutebruck devices by bypassing HTTP basic authentication and injecting commands via various CGI parameters. It supports multiple CVEs and achieves remote code execution as root.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Geutebruck G-Cam EEC-2xxx, G-Code EBC-21xx, EFD-22xx, ETHC-22xx, and EWPC-22xx devices running firmware versions <= 1.12.0.27, 1.12.13.2, or 1.12.14.5
No auth needed
Prerequisites: Network access to the target device · Vulnerable firmware version
devstral-2 · analyzed Apr 22, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_confirm
https://www.randorisec.fr/fr/udp-technology-ip-camera-vulnerabilities/
Third Party Advisory, US Government Resource x_refsource_confirm
https://us-cert.cisa.gov/ics/advisories/icsa-21-208-03

Scores

CVSS v3 9.8
EPSS 0.8724
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-306
Status published
Products (48)
geutebrueck/g-cam_ebc-2110_firmware 1.12.13.2
geutebrueck/g-cam_ebc-2110_firmware 1.12.14.5
geutebrueck/g-cam_ebc-2110_firmware < 1.12.0.27
geutebrueck/g-cam_ebc-2111_firmware 1.12.13.2
geutebrueck/g-cam_ebc-2111_firmware 1.12.14.5
geutebrueck/g-cam_ebc-2111_firmware < 1.12.0.27
geutebrueck/g-cam_ebc-2112_firmware 1.12.13.2
geutebrueck/g-cam_ebc-2112_firmware 1.12.14.5
geutebrueck/g-cam_ebc-2112_firmware < 1.12.0.27
geutebrueck/g-cam_efd-2241_firmware 1.12.13.2
... and 38 more
Published Sep 13, 2021
Tracked Since Feb 18, 2026