CRITICAL
CVE-2021-33045
CVSS
9.8
KEV
Description
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
Summary dbcve.org
This is an authentication bypass vulnerability in Dahua security products (likely IP cameras, NVRs, and similar devices) where the login process fails to properly validate identity credentials. Attackers can craft malicious data packets to circumvent the authentication mechanism and gain unauthorized access to the device without valid credentials.
Mitigation
Apply vendor-supplied firmware patches immediately. If patches are unavailable, restrict network access to affected devices using firewalls or VLANs, and monitor for unauthorized access attempts.
Weakness (CWE)
CWE-287
Improper Authentication
EPSS Score
99.59%
Probability of exploitation in next 30 days
99.9th percentile
References
http://packetstormsecurity.com/files/164423/Dahua-Authentication-Bypass.html
Exploit, Third Party Advisory, VDB Entry
http://seclists.org/fulldisclosure/2021/Oct/13
Exploit, Mailing List, Third Party Advisory
https://www.dahuasecurity.com/support/cybersecurity/details/957
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-33045
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.