CRITICAL

CVE-2021-33044

Dahuasecurity Ipc Hum7xxx Firmware 2021-09-15 CVSS v3.1
CVSS
9.8
KEV

Description

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

Summary dbcve.org

Dahua devices contain an authentication bypass vulnerability in the login process where attackers can bypass identity verification by constructing malicious data packets. This pre-authentication flaw allows unauthorized access without valid credentials, affecting device identity controls during the login mechanism.

Mitigation

Apply vendor-released firmware patches from Dahua for affected products; if patches unavailable, implement network segmentation and restrict management interface access to trusted networks/IPs to reduce attack surface.

Proof of Concept

Weakness (CWE)

CWE-287 Improper Authentication

EPSS Score

99.99%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE