S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-33044 Scanner

CVE-2021-33044 scanner - Authentication Bypass vulnerability in Some Dahua IP Camera, Video Intercom, PTZ Dome Camera, Thermal Camera devices

Est. Time~9 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
3
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-33044
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Some Dahua IP Camera, Video Intercom, PTZ Dome Camera, Thermal Camera devicesby n/a
Dahua IP Camera devices IPC-HX3XXX, IPC-HX5XXX, and IPC-HUM7XXX, Video Intercom devices VTO75X95X, VTO65XXX, and VTH542XH, PTZ Dome Camera SD1A1, SD22, SD49, SD50, SD52C, and SD6AL, Thermal TPC-BF1241, TPC-BF2221, TPC-SD2221, TPC-BF5XXX, TPC-SD8X21, and TPC-PT8X21B devices Buildtime before June, 2021.
Updated Aug 21, 2026View on NVD →
Detail

Dahua IP Camera, Video Intercom, PTZ Dome Camera, and Thermal Camera devices are used for video surveillance purposes in various residential and commercial settings. These products are equipped with advanced functionalities like motion detection, night vision, and remote access, enabling individuals to keep an eye on their premises from anywhere, anytime. 

CVE-2021-33044 vulnerability was recently detected in some Dahua products. This vulnerability involves the identity authentication bypass during the login process. Attackers can exploit this flaw by constructing malicious data packets that bypass device identity authentication, subsequently gaining unauthorized access to the device.

Exploiting this vulnerability can lead to significant security breaches, compromised user credentials, and malicious attacks on the network. Attackers can leverage the compromised devices as a tool for DDoS attacks or launch further cyber attacks on the organization's infrastructure. The result can be devastating to the organization’s bottom line and reputation.

In conclusion, with the help of s4e.io, users can stay updated on the latest vulnerabilities in their digital assets and take the necessary steps to protect their devices from potential threats. s4e.io provides users with a comprehensive understanding of their device’s security status with detailed reports and recommendations, empowering users to make informed decisions while navigating the digital landscape. Stay secured with s4e.io!

 

REFERENCES

Solution Advice

To mitigate the risks of this vulnerability, users are advised to take the following precautions:

  • Update the devices with the latest firmware available on the Dahua website.
  • Disable internet connectivity and remote access if not required.
  • Isolate the devices from the network, where possible, to prevent attackers from gaining access to the organization’s network.
  • Use strong and complex login credentials on the device and avoid using default logins that are easy to guess.
  • Monitor the device logs regularly for suspicious activities and modify the settings accordingly.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.