CRITICAL
CVE-2021-33044
CVSS
9.8
KEV
Description
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
Summary dbcve.org
Dahua devices contain an authentication bypass vulnerability in the login process where attackers can bypass identity verification by constructing malicious data packets. This pre-authentication flaw allows unauthorized access without valid credentials, affecting device identity controls during the login mechanism.
Mitigation
Apply vendor-released firmware patches from Dahua for affected products; if patches unavailable, implement network segmentation and restrict management interface access to trusted networks/IPs to reduce attack surface.
Weakness (CWE)
CWE-287
Improper Authentication
EPSS Score
99.99%
Probability of exploitation in next 30 days
100th percentile
References
http://packetstormsecurity.com/files/164423/Dahua-Authentication-Bypass.html
Exploit, Third Party Advisory, VDB Entry
http://seclists.org/fulldisclosure/2021/Oct/13
Exploit, Mailing List, Third Party Advisory
https://www.dahuasecurity.com/support/cybersecurity/details/957
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-33044
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.