PT-2021-20027 · Dahua · Dahua Ip Camera

·

CVE-2021-33044

·

Published

2021-06-13

·

Updated

2026-09-04

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dahua ipc-hum7xxx firmware Dahua ipc-hx3xxx firmware Dahua ipc-hx5xxx firmware Dahua sd1a1 firmware Dahua sd22 firmware Dahua sd49 firmware Dahua sd50 firmware Dahua sd52c firmware Dahua sd6al firmware Dahua tpc-bf1241 firmware Dahua tpc-bf2221 firmware Dahua tpc-bf5x01 firmware Dahua tpc-bf5x21 firmware Dahua tpc-pt8x21b firmware Dahua tpc-sd2221 firmware Dahua tpc-sd8x21 firmware Dahua vth-542xh firmware Dahua vto-65xxx firmware Dahua vto-75x95x firmware
Description An identity authentication bypass exists during the login process. Remote attackers can bypass device identity authentication by constructing malicious data packets. This issue is related to flaws in the authentication procedures of the Loopback mechanism and the RPC2 Login web interface authentication mechanism, which may allow an attacker to escalate privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12630
BDU:2026-12631
CVE-2021-33044

Affected Products

Dahua Ip Camera