CVE-2021-33544
HIGH EXPLOITED IN THE WILD NUCLEIMultiple Camera Devices - Command Injection
Title source: llmExploitation Summary
CVE-2021-33544 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io).
EIP tracks 1 public exploit from researchers including Titouan Lazard, Ibrahim Ayadhi, Sébastien Charbonnier, including a Metasploit module exploits/linux/http/geutebruck_cmdinject_cve_2021_335xx.
A Nuclei detection template is also available.
AI-analyzed exploit summary This Metasploit module exploits multiple authenticated command injection vulnerabilities in Geutebruck devices by bypassing HTTP basic authentication and injecting commands via various CGI parameters. It supports multiple CVEs and achieves remote code execution as root.
Description
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
Exploits (1)
This Metasploit module exploits multiple authenticated command injection vulnerabilities in Geutebruck devices by bypassing HTTP basic authentication and injecting commands via various CGI parameters. It supports multiple CVEs and achieves remote code execution as root.
Nuclei Templates (1)
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H