CVE-2021-33044: Dahua IP Camera Authentication Bypass Vulnerability
Dahua IP cameras and related products contain an authentication bypass vulnerability when the NetKeyboard type argument is specified by the client during authentication.
Other sources
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-33044?
CVE-2021-33044 is an identity authentication bypass vulnerability found in some Dahua products during the login process.
How severe is CVE-2021-33044?
CVE-2021-33044 has a severity rating of 9.8 (critical).
Which Dahua products are affected by CVE-2021-33044?
Dahua products with the following firmware versions are affected: IPC-HUM7xxx, IPC-HX3xxx, IPC-HX5xxx, SD1a1, SD22, SD41, SD50, SD52c, SD6al, TPC-BF1241, TPC-BF2221, TPC-BF5x01, TPC-PT8x21b, TPC-SD2221, TPC-SD8x21, VTO-65xxx, VTO-75x95x, VTH-542xh, and TPC-BF5x21.
How can attackers exploit CVE-2021-33044?
Attackers can exploit CVE-2021-33044 by bypassing device identity authentication using malicious data packets.
Where can I find more information about CVE-2021-33044?
More information about CVE-2021-33044 can be found at the following references: [link1], [link2], [link3].