ZeroHour

CVE-2021-33044

KEV PoC ×2mass1

Authentication Bypass in Dahua IP Camera Firmware

CISA: Dahua IP Camera Authentication Bypass Vulnerability

CVSS 3.1
9.8 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

Dahua IP cameras and related products contain an authentication bypass flaw (CWE-287, Improper Authentication) that is triggered when the client supplies the NetKeyboard type argument during the authentication process, allowing the device to treat the session as authenticated without valid credentials. An unauthenticated remote attacker who can reach the camera's network interface can exploit this to gain unauthorized access to the device's management functions. Successful exploitation can expose camera video streams and device configuration and can serve as a foothold into the surrounding surveillance or corporate network. Any organization running affected Dahua IP camera firmware, particularly cameras exposed to the internet, is potentially affected. The flaw is confirmed to be exploited in the wild: it was added to the CISA KEV on 2024-08-21, and EPSS assigns it a 99.9% probability of exploitation within 30 days (100th percentile), although no public PoC is known.

What to do: Apply the mitigations or patched firmware specified in Dahua's security advisory for CVE-2021-33044; if mitigations are unavailable, discontinue use of the product as CISA's required action directs. Inventory internet-facing Dahua cameras and related devices, restrict their login interfaces from direct internet exposure, and review authentication logs for signs of prior exploitation. Ransomware use is listed as unknown, so treat any compromised camera as a potential network foothold and rotate any credentials used on the device.

Affected
Dahua IP Camera Firmware
Estimated exposure
massplausibly millions of installed Dahua cameras worldwide, with likely >100,000 internet-exposed Dahua devices — Dahua is one of the world's largest video-surveillance vendors with an installed base measured in millions of devices, and public internet-wide scans (e.g., Shodan/Censys-type scans) routinely show on the order of 100,000+ exposed Dahua…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

CISA Known Exploited Vulnerability
Affected
Dahua IP Camera Firmware
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
dahuasecurity
Products
ipc-hum7xxx firmware, ipc-hx3xxx firmware, ipc-hx5xxx firmware, sd1a1 firmware, sd22 firmware, sd49 firmware, sd50 firmware, sd52c firmware, sd6al firmware, tpc-bf1241 firmware, tpc-bf2221 firmware, tpc-bf5x01 firmware
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

Sysdig documents a skilled human attacker exploiting Marimo pre-auth RCE CVE-2026-39987 (CVSS 9.3), reaching an SSH bastion in eight seconds without AI tooling.

Sysdig detailed exploitation of CVE-2026-39987 (CVSS 9.3), a pre-authenticated RCE affecting all Marimo versions that came under active exploitation within hours of disclosure. A human operator used a hand-written Python script to harvest an AWS key from Secrets Manager and SSH into a bastion host in eight seconds, issuing 850+ commands over nine hours. Separately, Hunt.io disclosed an XMRig cryptomining campaign compromising 3,562 Redis servers via SLAVEOF rogue replication and AOF authorized_keys injection. Operation CameraSwarm, linked to a single operator, compromised over 14,000 Dahua IP cameras using CVE-2021-33044 and CVE-2021-33045.

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

Hunt.io disclosed Operation CameraSwarm, compromising 14,500+ Dahua cameras via credential attacks, auth bypass CVEs, and P2P relay techniques across Ukraine and Russia.

Hunt.io reconstructed a campaign codenamed Operation CameraSwarm that compromised over 14,530 Dahua devices between June 17 and July 22, 2026. Attack paths included credential attacks against 12,324 IPs, exploitation of CVE-2021-33044 and CVE-2021-33045 affecting 1,923 cameras, and P2P relay access to 283 devices behind NAT. The operator, assessed as Russian-speaking, left behind 2,616 files including tooling and campaign logs, with confirmed compromises concentrated in Ukraine and Russia. Dahua advises factory resets and firmware updates; both 2021 CVEs remain in CISA's KEV catalog.

The Hacker News · 21d agoThreat actor in the wildCVE-2021-33044CVE-2021-33045CVE-2024-39943+1 CVEs1