CVE-2021-33544

HIGH EXPLOITED IN THE WILD NUCLEI

Multiple Camera Devices - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-33544 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 1 public exploit from researchers including Titouan Lazard, Ibrahim Ayadhi, Sébastien Charbonnier, including a Metasploit module exploits/linux/http/geutebruck_cmdinject_cve_2021_335xx. A Nuclei detection template is also available.

AI-analyzed exploit summary This Metasploit module exploits multiple authenticated command injection vulnerabilities in Geutebruck devices by bypassing HTTP basic authentication and injecting commands via various CGI parameters. It supports multiple CVEs and achieves remote code execution as root.

Description

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

Exploits (1)

metasploit WORKING POC EXCELLENT
by Titouan Lazard, Ibrahim Ayadhi, Sébastien Charbonnier · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/geutebruck_cmdinject_cve_2021_335xx.rb

This Metasploit module exploits multiple authenticated command injection vulnerabilities in Geutebruck devices by bypassing HTTP basic authentication and injecting commands via various CGI parameters. It supports multiple CVEs and achieves remote code execution as root.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Geutebruck G-Cam EEC-2xxx, G-Code EBC-21xx, EFD-22xx, ETHC-22xx, and EWPC-22xx devices running firmware versions <= 1.12.0.27, 1.12.13.2, or 1.12.14.5
No auth needed
Prerequisites: Network access to the target device · Vulnerable firmware version
devstral-2 · analyzed Apr 22, 2026 Full analysis →

Nuclei Templates (1)

Geutebruck - Remote Command Injection
HIGHby gy741

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource
https://us-cert.cisa.gov/ics/advisories/icsa-21-208-03

Scores

CVSS v3 7.2
EPSS 0.9425
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2021-09-20
InTheWild.io 2021-04-18
CWE
CWE-78
Status published
Products (48)
geutebrueck/g-cam_ebc-2110_firmware 1.12.13.2
geutebrueck/g-cam_ebc-2110_firmware 1.12.14.5
geutebrueck/g-cam_ebc-2110_firmware < 1.12.0.27
geutebrueck/g-cam_ebc-2111_firmware 1.12.13.2
geutebrueck/g-cam_ebc-2111_firmware 1.12.14.5
geutebrueck/g-cam_ebc-2111_firmware < 1.12.0.27
geutebrueck/g-cam_ebc-2112_firmware 1.12.13.2
geutebrueck/g-cam_ebc-2112_firmware 1.12.14.5
geutebrueck/g-cam_ebc-2112_firmware < 1.12.0.27
geutebrueck/g-cam_efd-2241_firmware 1.12.13.2
... and 38 more
Published Sep 13, 2021
Tracked Since Feb 18, 2026