Vulnerability record · CVE-2021-33044 · published 15 September 2021
CVE-2021-33044: Dahua IP cameras and recorders authentication bypass via crafted packets
Dahuasecurity · Ipc Hum7xxx Firmware
Multiple Dahua device firmware families contain an improper authentication flaw in the login process, allowing attackers to bypass identity authentication by sending specially constructed data packets. The vulnerability is remotely reachable without credentials and carries a critical CVSS score of 9.8, making it a serious exposure for internet-facing cameras, recorders and intercoms.
Description
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote authentication bypass with a 9.8 CVSS score, KEV listing, public exploits and near-maximum EPSS makes this an urgent patch-or-isolate case.
What it is
Multiple Dahua device firmware families contain an improper authentication flaw in the login process, allowing attackers to bypass identity authentication by sending specially constructed data packets. The vulnerability is remotely reachable without credentials and carries a critical CVSS score of 9.8, making it a serious exposure for internet-facing cameras, recorders and intercoms.
Impact
An attacker gains unauthenticated access to the device, which can lead to full compromise of confidentiality, integrity and availability, including device takeover and use as a pivot into the network.
Attack surface
Reached over the network via the login interface with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any device exposing the affected login service, including internet-facing units, is in scope.
Exploitation
The flaw is listed in CISA KEV with a 2024-08-21 addition date and a 2024-09-11 remediation due date, and public exploit references exist on Packet Storm and Full Disclosure. EPSS is 0.99871 (99.963rd percentile), indicating very high predicted exploitation activity.
What to do
- Apply the vendor firmware updates referenced in Dahua security advisory 957 for all affected product families.
- If patching is not possible, remove affected devices from direct internet exposure and place them behind a firewall or VPN.
- Disable or restrict remote login services and unnecessary ports on affected cameras, recorders and intercoms.
- Segment video surveillance devices onto an isolated VLAN with no access to corporate or production networks.
- Follow CISA KEV required action: apply vendor mitigations or discontinue use of the product if mitigations are unavailable.
Detection
- Monitor authentication and login logs on Dahua devices for successful logins without valid credentials or anomalous source IPs.
- Alert on unexpected configuration changes, new admin accounts or firmware modifications on surveillance devices.
- Inspect network traffic to device login endpoints for malformed or unusual authentication packets matching public exploit patterns.
- Track outbound connections from camera and recorder VLANs to external hosts as a possible sign of compromise.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-33044 to the Known Exploited Vulnerabilities catalog on 21 August 2024 as "Dahua IP Camera Authentication Bypass Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 11 September 2024.
Affected products
19 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/164423/Dahua-Authentication-Bypass.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2021/Oct/13 | ExploitMailing ListThird Party Advisory |
| https://www.dahuasecurity.com/support/cybersecurity/details/957 | Vendor Advisory |
| http://packetstormsecurity.com/files/164423/Dahua-Authentication-Bypass.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2021/Oct/13 | ExploitMailing ListThird Party Advisory |
| https://www.dahuasecurity.com/support/cybersecurity/details/957 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-33044 | US Government Resource |
Track CVE-2021-33044 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-33044), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.