CVE-2023-33443

CRITICAL

BES-6024PB-I50H1 VideoPlayTool <2.0.1.0 - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-33443. PoCs published by FallFur.

AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2023-33443, which bypasses QR captcha authentication on BESDER IP cameras and VideoPlayTool 2.0.1.0, allowing unauthenticated password changes for any user. The exploit interacts with a local VideoPlayTool instance and a Chinese server to decrypt captcha data and send crafted requests to the camera.

Description

Incorrect access control in the administrative functionalities of BES--6024PB-I50H1 VideoPlayTool v2.0.1.0 allow attackers to execute arbitrary administrative commands via a crafted payload sent to the desired endpoints.

Exploits (1)

gitlab WORKING POC 1 stars
by FallFur · poc
https://gitlab.com/FallFur/exploiting-unprotected-admin-funcionalities-on-besder-ip-cameras

This repository contains a functional Python exploit for CVE-2023-33443, which bypasses QR captcha authentication on BESDER IP cameras and VideoPlayTool 2.0.1.0, allowing unauthenticated password changes for any user. The exploit interacts with a local VideoPlayTool instance and a Chinese server to decrypt captcha data and send crafted requests to the camera.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: BESDER IP cameras, VideoPlayTool 2.0.1.0, XMEYE app
No auth needed
Prerequisites: VideoPlayTool 2.0.1.0 installed locally · QR captcha enabled on target camera · Network access to target camera and Chinese server (tools.xmeye.net)
devstral-2 · analyzed Feb 23, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0350
EPSS Percentile 87.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-346
Status published
Products (1)
besder/videoplaytool 2.0.1.0
Published Jun 08, 2023
Tracked Since Feb 18, 2026