CVE-2021-33045
Description
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
In plain language
AI Act nowCVE-2021-33045 lets anyone on the network log into certain Dahua devices without a password, and it has been exploited in the real world—so most affected small businesses should treat this as an urgent fix.
CVE-2021-33045 is an identity authentication bypass in the Dahua login process that allows unauthenticated attackers to remotely gain full access by sending specially crafted network packets; it is listed in CISA KEV and has been exploited in active campaigns.
What to do now
- Check whether any Dahua devices you use are in the affected product families (ipc-hum7xxx, ipc-hx3xxx, ipc-hx5xxx, nvr-1xxx, nvr-2xxx, nvr-4xxx, nvr-5xxx, nvr-6xx, vth-542xh, vto-65xxx) and note their exact firmware version.
- Compare your firmware version to the fixed versions below and plan an upgrade to the matching fixed release for your device family.
- Update immediately to one of these fixed firmware versions: ipc-hum7xxx → 2.820.0000000.5.r.210705; ipc-hx3xxx → 2.800.0000000.29.r.210630; ipc-hx5xxx → 2.820.0000000.5.r.210705; nvr-1xxx → 4.001.0000005.1.r.210709; nvr-2xxx → 4.001.0000000.1.r.210710; nvr-4xxx → 4.001.0000005.1.r.210713; nvr-5xxx → 4.001.0000000.0.r.210710; nvr-6xx → 4.001.0000001.1.r.210716; vth-542xh → 4.500.0000002.0.r.210715; vto-65xxx → 4.300.0000004.0.r.210715.
- If you cannot upgrade right away, follow Dahua’s mitigation guidance (or consider discontinuing use of the product) from the vendor remediation page, and restrict network access so the device is not reachable from untrusted networks.
- After patching, review the device for signs of persistent unauthorized access (for example, unexpected users/accounts) and monitor device/network logs for repeated login or unusual connection attempts.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russiaen-us·SecurityWeek· Exploited Dahua IP Cameras Threat Actor (Operation CameraSwarm)
- Хакеры взломали 14 500 камер Dahua всего за 35 днейru-ru·Хакер (xakep.ru)· Exploited Dahua IP Cameras ics-ot-iot
- Hackers compromise 14,500 Dahua web cameras in 35-day campaignen-us·BleepingComputer· Exploited Dahua IP Cameras ics-ot-iot
- Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2Pen·The Hacker News·
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2021-33045 and every CVE in our database. Create a free account — no credit card required.
Create Free Account