CVE-2021-33551

HIGH EXPLOITED IN THE WILD

Multiple Camera Devices - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-33551 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 1 public exploit from researchers including Titouan Lazard, Ibrahim Ayadhi, Sébastien Charbonnier, including a Metasploit module exploits/linux/http/geutebruck_cmdinject_cve_2021_335xx.

AI-analyzed exploit summary This Metasploit module exploits multiple authenticated command injection vulnerabilities in Geutebruck devices by bypassing HTTP basic authentication and injecting commands via various CGI parameters. It supports multiple CVEs (2021-33543, 2021-33544, 2021-33548, 2021-33550, 2021-33551, 2021-33552, 2021-33553, 2021-33554) and results in remote code execution as root.

Description

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

Exploits (1)

metasploit WORKING POC EXCELLENT
by Titouan Lazard, Ibrahim Ayadhi, Sébastien Charbonnier · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/geutebruck_cmdinject_cve_2021_335xx.rb

This Metasploit module exploits multiple authenticated command injection vulnerabilities in Geutebruck devices by bypassing HTTP basic authentication and injecting commands via various CGI parameters. It supports multiple CVEs (2021-33543, 2021-33544, 2021-33548, 2021-33550, 2021-33551, 2021-33552, 2021-33553, 2021-33554) and results in remote code execution as root.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Geutebruck G-Cam EEC-2xxx, G-Code EBC-21xx, EFD-22xx, ETHC-22xx, EWPC-22xx devices running firmware versions <= 1.12.0.27, 1.12.13.2, or 1.12.14.5
No auth needed
Prerequisites: Network access to the target device · Target device running vulnerable firmware
devstral-2 · analyzed Apr 22, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource
https://us-cert.cisa.gov/ics/advisories/icsa-21-208-03

Scores

CVSS v3 7.2
EPSS 0.8395
EPSS Percentile 99.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2023-10-09
InTheWild.io 2023-10-10
CWE
CWE-78
Status published
Products (48)
geutebrueck/g-cam_ebc-2110_firmware 1.12.13.2
geutebrueck/g-cam_ebc-2110_firmware 1.12.14.5
geutebrueck/g-cam_ebc-2110_firmware < 1.12.0.27
geutebrueck/g-cam_ebc-2111_firmware 1.12.13.2
geutebrueck/g-cam_ebc-2111_firmware 1.12.14.5
geutebrueck/g-cam_ebc-2111_firmware < 1.12.0.27
geutebrueck/g-cam_ebc-2112_firmware 1.12.13.2
geutebrueck/g-cam_ebc-2112_firmware 1.12.14.5
geutebrueck/g-cam_ebc-2112_firmware < 1.12.0.27
geutebrueck/g-cam_efd-2241_firmware 1.12.13.2
... and 38 more
Published Sep 13, 2021
Tracked Since Feb 18, 2026