← Vulnerability feed

Vulnerability record · CVE-2021-33045 · published 15 September 2021

CVE-2021-33045: Dahua IP cameras and NVRs authentication bypass via crafted packets

Dahuasecurity · Ipc Hum7xxx Firmware

Dahua IP cameras, NVRs, XVRs and related devices contain an improper authentication flaw (CWE-287) in the login process. An attacker can bypass device identity authentication by sending specially constructed network packets, gaining access without valid credentials. The flaw is rated CVSS 9.8 critical and affects a broad range of Dahua firmware families.

9.8 CVSS 3.1 Critical CISA KEV since 21 Aug 2024 EPSS 100% · top 0.1% CWE-287 · Improper authentication
9.8CVSS 3.1 base score, v2 10.0
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
18Affected product versions listed by NVD
7References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8 unauthenticated network authentication bypass, listed in CISA KEV with public exploits and near-maximum EPSS probability.

What it is

Dahua IP cameras, NVRs, XVRs and related devices contain an improper authentication flaw (CWE-287) in the login process. An attacker can bypass device identity authentication by sending specially constructed network packets, gaining access without valid credentials. The flaw is rated CVSS 9.8 critical and affects a broad range of Dahua firmware families.

Impact

An unauthenticated attacker gains full access to the affected device, with high impact to confidentiality, integrity and availability. This can expose live video, allow configuration changes, and provide a foothold into the camera or recorder network.

Attack surface

The flaw is reachable over the network via the device login process, as reflected by the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required; the attacker only needs network reachability to the device's login service.

Exploitation

CVE-2021-33045 is listed in CISA KEV (added 2024-08-21) and has public exploit references, and EPSS shows a 30-day probability of 0.99556 (99.9th percentile), indicating active exploitation is expected. No ransomware campaign use is documented in the record.

What to do

  • Apply the vendor's fixed firmware per the Dahua security advisory (details/957) for all listed camera, NVR, XVR, VTO and VTH models.
  • If patching is not possible, isolate affected devices on a segmented network with no internet exposure and restrict management access to trusted hosts.
  • Disable or block remote access to the device login service from untrusted networks using firewall rules.
  • Replace or discontinue devices that cannot be updated, per CISA KEV required action.
  • Monitor vendor advisories for updated firmware and re-check affected model coverage.

Detection

  • Monitor authentication and login logs on Dahua devices for successful logins without a preceding valid credential exchange or from unexpected source IPs.
  • Alert on anomalous or malformed packets directed at the device login service, including repeated connection attempts from a single external host.
  • Baseline normal management traffic and flag new external IPs reaching camera/NVR management ports.
  • Review network flow logs for affected device models communicating with untrusted external addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-33045 to the Known Exploited Vulnerabilities catalog on 21 August 2024 as "Dahua IP Camera Authentication Bypass Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 11 September 2024.

Affected products

18 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-33045 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-33044Dahua IP cameras and recorders authentication bypass via crafted packetsMultiple Dahua device firmware families contain an improper authentication flaw in the login process, allowing attackers to bypass identity authentic…KEVEPSS 100%analysed9.8CVE-2021-33046Dahuasecurity ipc-hx1xxx firmware improper authentication vulnerabilitySome Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerability through specific deploy…EPSS 1.3%7.5CVE-2026-42018JFrog Artifactory improper authentication leaks anonymous tokenJFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token …KEVEPSS 9.8%analysed9.8CVE-2026-82329JFrog Artifactory improper authentication allows admin takeoverJFrog Artifactory contains an improper authentication weakness (CWE-287) that, under default configuration, may let an unauthenticated attacker with …KEVEPSS 14%analysed8.8CVE-2026-59822LiteLLM MCP endpoint auth bypass via OAuth2 passthrough fallbackLiteLLM's MCP Streamable HTTP endpoint, prior to 1.84.0, let an unauthenticated attacker send a fabricated Authorization header that triggered an OAu…KEVEPSS 0.84%analysed10.0CVE-2026-49869Kestra OSS auth bypass via path suffix match enables RCEKestra OSS AuthenticationFilter whitelists the public config endpoint using request.getPath().endsWith("/configs"), a suffix match instead of an exac…KEVEPSS 2.1%analysed9.8CVE-2023-49105ownCloud Server WebDAV authentication bypass via pre-signed URLsownCloud core before 10.13.1 accepts pre-signed URLs even when the file owner has no signing-key configured, so the signature check is effectively sk…KEVEPSS 43%analysed9.8CVE-2026-65400Apple macOS Screen Sharing authentication bypassAn improper authentication flaw in Apple macOS Screen Sharing allows a network attacker to authenticate without valid credentials. Apple fixed it via…KEVEPSS 1.2%analysed

Source: NIST National Vulnerability Database (record CVE-2021-33045), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.