LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-33044: Dahua IP Camera Authentication Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 21, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 11, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-33044 to its Known Exploited Vulnerabilities catalog on Aug 21, 2024, with a federal patch deadline of Sep 11, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Dahua IP cameras and related products contain an authentication bypass vulnerability when the NetKeyboard type argument is specified by the client during authentication.

CVE-2021-33044 is an authentication bypass vulnerability affecting Dahua IP camera firmware and related products. It allows an attacker to circumvent normal login controls when a specific argument is supplied during the authentication process. For IT and security teams, this matters because unauthenticated access to cameras can expose live video feeds, stored recordings, network credentials, or a foothold for further lateral movement inside the environment.

CISA notes that the flaw is triggered when the NetKeyboard type argument is specified by the client. Public detail beyond that summary is limited; teams should treat any internet-facing or poorly segmented Dahua devices as high priority until they confirm their firmware status against the vendor advisory.

How it works

The underlying weakness is CWE-287 (Improper Authentication). In products of this class, the authentication routine fails to enforce proper credential checks when a particular client-supplied parameter—in this case the NetKeyboard type argument—is present. An attacker who can reach the device’s authentication interface can therefore present a crafted request that the firmware accepts as valid without requiring legitimate credentials.

Because the bypass occurs at the authentication layer, successful exploitation typically grants the same privileges that a legitimate authenticated user would receive. Exact request formats, required parameters beyond the NetKeyboard argument, and resulting privilege levels are not detailed in the available summary; defenders must consult the vendor advisory for precise technical indicators rather than relying on incomplete public descriptions.

Am I affected? How to find it in your systems

Dahua IP cameras and related products are commonly deployed for physical security monitoring in offices, warehouses, campuses, and remote sites. They may appear on both corporate and guest networks, often with web or RTSP interfaces exposed for management or viewing.

If version or configuration data cannot be obtained remotely, schedule physical or out-of-band checks; do not assume a device is safe simply because it is not internet-facing.

How to remediate

The primary remediation is to apply the vendor-supplied firmware update that addresses CVE-2021-33044. CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Confirm the exact fixed firmware releases, download sources, and installation procedures directly from the official Dahua advisory; do not rely on third-party mirrors.

Document the before-and-after firmware versions for audit purposes.

If you can't patch immediately

Until the official update can be installed, reduce exposure with compensating controls appropriate to an authentication-bypass class of flaw:

These measures lower risk but do not eliminate it; plan to apply the vendor patch as soon as operationally feasible. If mitigations prove unavailable or insufficient, CISA guidance is to discontinue use of the product.

If your data may have been exposed

Actively exploited authentication-bypass vulnerabilities on cameras can lead to unauthorized viewing or exfiltration of video, credentials, or network reconnaissance data. Known ransomware use of this specific CVE is not documented, yet any compromise should still be treated as a potential breach. Review camera logs and network telemetry for signs of unauthorized access, rotate any credentials that may have been stored on or used by the devices, and consider whether recorded footage or adjacent systems require further investigation. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether related accounts appear in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedDahua · IP Camera Firmware
WeaknessCWE-287
Added to CISA KEVAug 21, 2024
Federal patch deadlineSep 11, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities