CVE-2021-33045
Dahua IP Camera Authentication Bypass Vulnerability
Description
CVE-2021-33045 is a critical authentication bypass vulnerability (CVSS 9.8) in Dahua IP camera and video surveillance firmware. The flaw exists in the login process of multiple Dahua product lines including IP cameras, network video recorders (NVRs), video intercoms, and XVR recorders. Attackers can bypass device identity authentication by constructing malicious data packets, gaining unauthorized access to the surveillance system without valid credentials. This vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. With an extraordinary EPSS score of 94.17% (99.9th percentile), this is among the most likely-to-be-exploited vulnerabilities globally.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| dahuasecurity | ipc-hum7xxx firmware | < 2.820.0000000.5.r.210705 |
| dahuasecurity | ipc-hx3xxx firmware | < 2.800.0000000.29.r.210630 |
| dahuasecurity | ipc-hx5xxx firmware | < 2.820.0000000.5.r.210705 |
| dahuasecurity | nvr-1xxx firmware | < 4.001.0000005.1.r.210709 |
| dahuasecurity | nvr-2xxx firmware | < 4.001.0000000.1.r.210710 |
| dahuasecurity | nvr-4xxx firmware | < 4.001.0000005.1.r.210713 |
| dahuasecurity | nvr-5xxx firmware | < 4.001.0000000.0.r.210710 |
| dahuasecurity | nvr-6xx firmware | < 4.001.0000001.1.r.210716 |
| dahuasecurity | vth-542xh firmware | < 4.500.0000002.0.r.210715 |
| dahuasecurity | vto-65xxx firmware | < 4.300.0000004.0.r.210715 |
| dahuasecurity | vto-75x95x firmware | < 4.300.0000003.0.r.210714 |
| dahuasecurity | xvr-4x04 firmware | -; < 4.001.0000001.1.r.210709 |
| dahuasecurity | xvr-4x08 firmware | < 4.001.0000001.1.r.210709 |
| dahuasecurity | xvr-5x04 firmware | < 4.001.0000003.1.r.210710 |
| dahuasecurity | xvr-5x08 firmware | < 4.001.0000003.1.r.210710 |
| dahuasecurity | xvr-5x16 firmware | < 4.001.0000003.1.r.210710 |
| dahuasecurity | xvr-7x16 firmware | < 4.001.0000003.1.r.210710 |
| dahuasecurity | xvr-7x32 firmware | < 4.001.0000003.1.r.210710 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
- http://packetstormsecurity.com/files/164423/Dahua-Authentication-Bypass.html(Exploit, Third Party Advisory, VDB Entry)
- http://seclists.org/fulldisclosure/2021/Oct/13(Exploit, Mailing List, Third Party Advisory)
- https://www.dahuasecurity.com/support/cybersecurity/details/957(Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-33045(US Government Resource)
Weakness Type
Authentication Bypass
This vulnerability is an identity authentication bypass in Dahua's device login process. Authentication bypass vulnerabilities allow attackers to circumvent the intended authentication mechanisms entirely, gaining access to protected resources without providing valid credentials. In the case of CVE-2021-33045, the flaw exists in how Dahua devices process login requests — attackers can construct specially crafted data packets that trick the device into granting access without verifying identity. Authentication bypass vulnerabilities in IoT devices like surveillance cameras are particularly concerning because these devices are often internet-accessible, rarely receive timely updates, and provide access to sensitive video feeds and physical security systems. The widespread deployment of Dahua products across commercial, government, and residential installations amplifies the impact significantly.
Impact Analysis
The CVSS score of 9.8 (Critical) represents near-maximum severity, reflecting the devastating potential of unauthenticated access to surveillance infrastructure. Confidentiality impact is rated High, as an attacker who bypasses authentication gains access to live video feeds, recorded footage, audio streams, and device configuration data including network settings and potentially stored credentials. Integrity impact is also High, allowing attackers to modify camera settings, disable recording, alter motion detection zones, delete footage, or redirect video feeds. Availability impact is High as well, since attackers could disable cameras, disrupt recording systems, or render the entire surveillance infrastructure non-functional.
The business implications extend beyond data theft to physical security concerns. Compromised surveillance systems can be used for physical reconnaissance before burglaries or attacks, corporate espionage through video monitoring of sensitive areas, sabotage by disabling security cameras during an intrusion, and as pivot points into the broader corporate network. The EPSS score of 94.17% (99.9th percentile) places this among the most exploited vulnerabilities globally. Public exploits are available through Packet Storm Security and the Full Disclosure mailing list, making exploitation trivially accessible. While the ransomware association is unknown, compromised IoT devices are frequently recruited into botnets for DDoS attacks and used as network footholds.
Exploit Maturity
CVE-2021-33045 is confirmed as actively exploited in the wild, with CISA listing it in the Known Exploited Vulnerabilities catalog with a remediation deadline of September 11, 2024. The EPSS score of 94.17% (99.9th percentile) indicates near-certain exploitation probability, making it one of the most targeted vulnerabilities globally. Multiple public exploits are readily available: a detailed exploitation tool has been published on Packet Storm Security, and a full disclosure write-up with exploit code was posted to the Full Disclosure mailing list. The combination of a trivially exploitable authentication bypass, widespread deployment of Dahua devices, and freely available exploit code creates a perfect storm for mass exploitation. Automated scanning tools actively probe for vulnerable Dahua devices across the internet. While the ransomware association is unknown, compromised surveillance devices are frequently leveraged for botnet recruitment, network pivoting, and persistent access.
Remediation
-
Update Dahua device firmware immediately — Consult the Dahua security advisory for the specific patched firmware version for each affected product line. Download the appropriate firmware from Dahua's official support portal and apply the update through the device's web interface or management platform.
-
Isolate surveillance devices from the internet — Dahua cameras and NVRs should never be directly exposed to the public internet. Place all surveillance devices on a dedicated, segmented VLAN with strict firewall rules that only permit necessary traffic. Use a VPN for remote access to surveillance systems instead of port forwarding.
-
Change all default credentials — Reset all device passwords to strong, unique credentials. Replace any factory-default usernames and passwords across all Dahua devices in your deployment. Enable account lockout policies where supported to prevent brute-force attacks.
-
Audit network exposure of surveillance devices — Scan your network perimeter to identify any Dahua devices that are accessible from the internet, whether intentionally or through UPnP port forwarding. Use tools like Shodan or Censys to verify that your devices are not publicly visible. Disable UPnP on routers connected to surveillance networks.
-
Implement network monitoring for IoT devices — Deploy network detection tools that can identify anomalous traffic patterns from surveillance devices, such as unexpected outbound connections, unusual bandwidth usage, or communication with known malicious infrastructure. Set up alerts for authentication failures and configuration changes on surveillance devices.
Technical Details
The CVSS v3.1 vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H represents the worst-case exploitability scenario. Attack Vector (Network) means the vulnerability is remotely exploitable over any network connection, including the internet. Attack Complexity (Low) indicates no special conditions or preparation are required. Privileges Required (None) confirms that no authentication whatsoever is needed — the entire point of this vulnerability is bypassing authentication. User Interaction (None) means the attack is fully automated with no victim involvement required. Scope (Unchanged) keeps the impact within the device context, though compromised devices can be used to attack other network resources.
The vulnerability resides in the authentication handling logic of the Dahua device login process. When a Dahua device receives a login request, it processes the authentication data through a series of validation steps. The flaw allows an attacker to craft malicious data packets that bypass the identity verification checks during this process. Specifically, by manipulating certain fields in the authentication protocol, the attacker can cause the device to accept the login without actually validating the provided credentials against the stored authentication database. This results in the attacker being granted an authenticated session with full administrative privileges over the device. The exploit is reliable, requires no user interaction, and can be automated to scan and compromise large numbers of Dahua devices across the internet. The wide range of affected products — from IP cameras and NVRs to video intercoms and XVR recorders — means that virtually all Dahua surveillance deployments using firmware versions prior to the July 2021 patches are vulnerable.
Frequently Asked Questions
What is CVE-2021-33045?
CVE-2021-33045 is a critical authentication bypass vulnerability affecting a wide range of Dahua surveillance products including IP cameras, network video recorders, video intercoms, and XVR recorders. It allows remote attackers to bypass device authentication entirely by crafting malicious login packets, gaining full unauthorized access without valid credentials.
Which Dahua products are affected?
The vulnerability affects numerous Dahua product families including IPC-HUM7xxx, IPC-HX3xxx, IPC-HX5xxx series IP cameras, NVR-1xxx through NVR-6xx series network video recorders, VTH-542xH video intercoms, VTO-65xxx and VTO-75x95x door stations, and XVR-4x04 through XVR-7x32 digital video recorders. Each product line has specific firmware versions that must be updated.
Can this vulnerability be exploited remotely over the internet?
Yes, this vulnerability can be exploited remotely by any attacker who can reach the device over the network. Many Dahua devices are unintentionally exposed to the internet through port forwarding or UPnP, making them directly attackable. The EPSS score of 94.17% confirms that exploitation is occurring at massive scale.
How does CVE-2021-33045 relate to CVE-2021-33044?
Both CVEs are authentication bypass vulnerabilities in Dahua products disclosed at the same time, affecting overlapping but distinct sets of products. CVE-2021-33044 affects additional product lines including thermal cameras and SD PTZ cameras. Both should be patched simultaneously through the same firmware update process.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.