CVE-2021-33551
HIGH EXPLOITED IN THE WILDMultiple Camera Devices - Command Injection
Title source: llmExploitation Summary
CVE-2021-33551 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io).
EIP tracks 1 public exploit from researchers including Titouan Lazard, Ibrahim Ayadhi, Sébastien Charbonnier, including a Metasploit module exploits/linux/http/geutebruck_cmdinject_cve_2021_335xx.
AI-analyzed exploit summary This Metasploit module exploits multiple authenticated command injection vulnerabilities in Geutebruck devices by bypassing HTTP basic authentication and injecting commands via various CGI parameters. It supports multiple CVEs (2021-33543, 2021-33544, 2021-33548, 2021-33550, 2021-33551, 2021-33552, 2021-33553, 2021-33554) and results in remote code execution as root.
Description
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
Exploits (1)
This Metasploit module exploits multiple authenticated command injection vulnerabilities in Geutebruck devices by bypassing HTTP basic authentication and injecting commands via various CGI parameters. It supports multiple CVEs (2021-33543, 2021-33544, 2021-33548, 2021-33550, 2021-33551, 2021-33552, 2021-33553, 2021-33554) and results in remote code execution as root.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H