Vulnerability record · CVE-2021-33552 · published 13 September 2021
CVE-2021-33552: Geutebrück and UDP Technology cameras command injection
Geutebrueck · G Cam Ebc 2110 Firmware
Multiple Geutebrück G-Cam and G-Code camera devices (and other UDP Technology-based cameras) are vulnerable to OS command injection, allowing remote arbitrary code execution. The flaw is in the camera firmware itself, so any exposed device is a potential foothold on the network.
Description
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution on internet-adjacent camera devices with a public exploit and very high EPSS, though exploitation requires valid admin credentials.
What it is
Multiple Geutebrück G-Cam and G-Code camera devices (and other UDP Technology-based cameras) are vulnerable to OS command injection, allowing remote arbitrary code execution. The flaw is in the camera firmware itself, so any exposed device is a potential foothold on the network.
Impact
An attacker who can reach the device and authenticate can execute arbitrary OS commands, gaining full control of the camera and a pivot point into the surveillance network.
Attack surface
Reachable over the network via the camera's web/management interface (CVSS vector AV:N). The vector requires high privileges (PR:H), so valid administrative credentials are needed; no user interaction is required.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.488, ~98.8th percentile) and a public exploit reference exists, indicating meaningful real-world exploitation risk.
What to do
- Apply the vendor firmware updates referenced in CISA ICS advisory ICSA-21-208-03 as soon as they are available for each affected model.
- Isolate cameras on a dedicated VLAN with no route to corporate or internet-facing networks.
- Remove or restrict remote management access; block camera admin interfaces from untrusted networks.
- Change default and weak administrative credentials and enforce strong unique passwords.
- Monitor vendor advisories for these end-of-life-prone camera models and plan replacement if no fix is issued.
Detection
- Alert on unexpected outbound connections or command-shell activity originating from camera IP addresses.
- Monitor camera admin logins for anomalous source IPs, brute-force patterns, or logins outside maintenance windows.
- Inspect HTTP requests to camera management endpoints for shell metacharacters or command-injection payloads.
- Baseline normal camera traffic and flag deviations such as new listening ports or unusual processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
16 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://us-cert.cisa.gov/ics/advisories/icsa-21-208-03 | Third Party AdvisoryUS Government Resource |
| https://www.randorisec.fr/fr/udp-technology-ip-camera-vulnerabilities/ | ExploitThird Party Advisory |
| https://us-cert.cisa.gov/ics/advisories/icsa-21-208-03 | Third Party AdvisoryUS Government Resource |
| https://www.randorisec.fr/fr/udp-technology-ip-camera-vulnerabilities/ | ExploitThird Party Advisory |
Track CVE-2021-33552 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-33552), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.