CVE-2021-33544
UDP Technology/Geutebrück camera devices: command injection leading to RCE
Record summary
CVE-2021-33544 has a selected CVSS score of 7.2 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
Exploitation context
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
E2 SeriesBrowse Geutebrück / E2 Series | CVE List | EBC-21xx 1.12.13.2 | affected |
| EBC-21xx 1.12.14.5 | affected | ||
| EFD-22xx 1.12.13.2 | affected | ||
| EFD-22xx 1.12.14.5 | affected | ||
| ETHC-22xx 1.12.13.2 | affected | ||
| ETHC-22xx 1.12.14.5 | affected | ||
| EWPC-22xx 1.12.13.2 | affected | ||
| EWPC-22xx 1.12.14.5 | affected | ||
| EBC-21xx to ≤ 1.12.0.27 | affected | ||
| EFD-22xx to ≤ 1.12.0.27 | affected | ||
| ETHC-22xx to ≤ 1.12.0.27 | affected | ||
| EWPC-22xx to ≤ 1.12.0.27 | affected | ||
Encoder G-CodeBrowse Geutebrück / Encoder G-Code | CVE List | EEC-2xx 1.12.13.2 | affected |
| EEC-2xx 1.12.14.5 | affected | ||
| EEN-20xx 1.12.13.2 | affected | ||
| EEN-20xx 1.12.14.5 | affected | ||
| EEC-2xx to ≤ 1.12.0.27 | affected | ||
| EEN-20xx to ≤ 1.12.0.27 | affected | ||
g-cam_ebc-2110Browse geutebruck / g-cam_ebc-2110 | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
MetasploitGeutebruck Multiple Remote Command ExecutionMetasploit exploitby Ibrahim Ayadhi +2 moreNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHGeutebruck - Remote Command InjectionCVSS 7.2
Geutebruck is susceptible to multiple vulnerabilities its web-based management interface that could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device.
Impact
Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands on the affected device, leading to unauthorized access, data theft, or further compromise of the network.
Remediation
Apply the latest security patches or firmware updates provided by Geutebruck to mitigate the vulnerability.
Source: ProjectDiscovery