← Vulnerability feed

Vulnerability record · CVE-2021-33044 · published 15 September 2021

CVE-2021-33044: Dahua IP cameras and recorders authentication bypass via crafted packets

Dahuasecurity · Ipc Hum7xxx Firmware

Multiple Dahua device firmware families contain an improper authentication flaw in the login process, allowing attackers to bypass identity authentication by sending specially constructed data packets. The vulnerability is remotely reachable without credentials and carries a critical CVSS score of 9.8, making it a serious exposure for internet-facing cameras, recorders and intercoms.

9.8 CVSS 3.1 Critical CISA KEV since 21 Aug 2024 EPSS 100% · top 0.1% CWE-287 · Improper authentication
9.8CVSS 3.1 base score, v2 10.0
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
19Affected product versions listed by NVD
7References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated remote authentication bypass with a 9.8 CVSS score, KEV listing, public exploits and near-maximum EPSS makes this an urgent patch-or-isolate case.

What it is

Multiple Dahua device firmware families contain an improper authentication flaw in the login process, allowing attackers to bypass identity authentication by sending specially constructed data packets. The vulnerability is remotely reachable without credentials and carries a critical CVSS score of 9.8, making it a serious exposure for internet-facing cameras, recorders and intercoms.

Impact

An attacker gains unauthenticated access to the device, which can lead to full compromise of confidentiality, integrity and availability, including device takeover and use as a pivot into the network.

Attack surface

Reached over the network via the login interface with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any device exposing the affected login service, including internet-facing units, is in scope.

Exploitation

The flaw is listed in CISA KEV with a 2024-08-21 addition date and a 2024-09-11 remediation due date, and public exploit references exist on Packet Storm and Full Disclosure. EPSS is 0.99871 (99.963rd percentile), indicating very high predicted exploitation activity.

What to do

  • Apply the vendor firmware updates referenced in Dahua security advisory 957 for all affected product families.
  • If patching is not possible, remove affected devices from direct internet exposure and place them behind a firewall or VPN.
  • Disable or restrict remote login services and unnecessary ports on affected cameras, recorders and intercoms.
  • Segment video surveillance devices onto an isolated VLAN with no access to corporate or production networks.
  • Follow CISA KEV required action: apply vendor mitigations or discontinue use of the product if mitigations are unavailable.

Detection

  • Monitor authentication and login logs on Dahua devices for successful logins without valid credentials or anomalous source IPs.
  • Alert on unexpected configuration changes, new admin accounts or firmware modifications on surveillance devices.
  • Inspect network traffic to device login endpoints for malformed or unusual authentication packets matching public exploit patterns.
  • Track outbound connections from camera and recorder VLANs to external hosts as a possible sign of compromise.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-33044 to the Known Exploited Vulnerabilities catalog on 21 August 2024 as "Dahua IP Camera Authentication Bypass Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 11 September 2024.

Affected products

19 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-33044 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-33045Dahua IP cameras and NVRs authentication bypass via crafted packetsDahua IP cameras, NVRs, XVRs and related devices contain an improper authentication flaw (CWE-287) in the login process. An attacker can bypass devic…KEVEPSS 100%analysed9.8CVE-2021-33046Dahuasecurity ipc-hx1xxx firmware improper authentication vulnerabilitySome Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerability through specific deploy…EPSS 1.3%7.5CVE-2026-42018JFrog Artifactory improper authentication leaks anonymous tokenJFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token …KEVEPSS 9.8%analysed9.8CVE-2026-82329JFrog Artifactory improper authentication allows admin takeoverJFrog Artifactory contains an improper authentication weakness (CWE-287) that, under default configuration, may let an unauthenticated attacker with …KEVEPSS 14%analysed8.8CVE-2026-59822LiteLLM MCP endpoint auth bypass via OAuth2 passthrough fallbackLiteLLM's MCP Streamable HTTP endpoint, prior to 1.84.0, let an unauthenticated attacker send a fabricated Authorization header that triggered an OAu…KEVEPSS 0.84%analysed10.0CVE-2026-49869Kestra OSS auth bypass via path suffix match enables RCEKestra OSS AuthenticationFilter whitelists the public config endpoint using request.getPath().endsWith("/configs"), a suffix match instead of an exac…KEVEPSS 2.1%analysed9.8CVE-2023-49105ownCloud Server WebDAV authentication bypass via pre-signed URLsownCloud core before 10.13.1 accepts pre-signed URLs even when the file owner has no signing-key configured, so the signature check is effectively sk…KEVEPSS 43%analysed9.8CVE-2026-65400Apple macOS Screen Sharing authentication bypassAn improper authentication flaw in Apple macOS Screen Sharing allows a network attacker to authenticate without valid credentials. Apple fixed it via…KEVEPSS 1.2%analysed

Source: NIST National Vulnerability Database (record CVE-2021-33044), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.