Vulnerability record · CVE-2021-33045 · published 15 September 2021
CVE-2021-33045: Dahua IP cameras and NVRs authentication bypass via crafted packets
Dahuasecurity · Ipc Hum7xxx Firmware
Dahua IP cameras, NVRs, XVRs and related devices contain an improper authentication flaw (CWE-287) in the login process. An attacker can bypass device identity authentication by sending specially constructed network packets, gaining access without valid credentials. The flaw is rated CVSS 9.8 critical and affects a broad range of Dahua firmware families.
Description
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 unauthenticated network authentication bypass, listed in CISA KEV with public exploits and near-maximum EPSS probability.
What it is
Dahua IP cameras, NVRs, XVRs and related devices contain an improper authentication flaw (CWE-287) in the login process. An attacker can bypass device identity authentication by sending specially constructed network packets, gaining access without valid credentials. The flaw is rated CVSS 9.8 critical and affects a broad range of Dahua firmware families.
Impact
An unauthenticated attacker gains full access to the affected device, with high impact to confidentiality, integrity and availability. This can expose live video, allow configuration changes, and provide a foothold into the camera or recorder network.
Attack surface
The flaw is reachable over the network via the device login process, as reflected by the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required; the attacker only needs network reachability to the device's login service.
Exploitation
CVE-2021-33045 is listed in CISA KEV (added 2024-08-21) and has public exploit references, and EPSS shows a 30-day probability of 0.99556 (99.9th percentile), indicating active exploitation is expected. No ransomware campaign use is documented in the record.
What to do
- Apply the vendor's fixed firmware per the Dahua security advisory (details/957) for all listed camera, NVR, XVR, VTO and VTH models.
- If patching is not possible, isolate affected devices on a segmented network with no internet exposure and restrict management access to trusted hosts.
- Disable or block remote access to the device login service from untrusted networks using firewall rules.
- Replace or discontinue devices that cannot be updated, per CISA KEV required action.
- Monitor vendor advisories for updated firmware and re-check affected model coverage.
Detection
- Monitor authentication and login logs on Dahua devices for successful logins without a preceding valid credential exchange or from unexpected source IPs.
- Alert on anomalous or malformed packets directed at the device login service, including repeated connection attempts from a single external host.
- Baseline normal management traffic and flag new external IPs reaching camera/NVR management ports.
- Review network flow logs for affected device models communicating with untrusted external addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-33045 to the Known Exploited Vulnerabilities catalog on 21 August 2024 as "Dahua IP Camera Authentication Bypass Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 11 September 2024.
Affected products
18 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/164423/Dahua-Authentication-Bypass.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2021/Oct/13 | ExploitMailing ListThird Party Advisory |
| https://www.dahuasecurity.com/support/cybersecurity/details/957 | Vendor Advisory |
| http://packetstormsecurity.com/files/164423/Dahua-Authentication-Bypass.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2021/Oct/13 | ExploitMailing ListThird Party Advisory |
| https://www.dahuasecurity.com/support/cybersecurity/details/957 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-33045 | US Government Resource |
Track CVE-2021-33045 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-33045), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.