LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-33045: Dahua IP Camera Authentication Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 21, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 11, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-33045 to its Known Exploited Vulnerabilities catalog on Aug 21, 2024, with a federal patch deadline of Sep 11, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Dahua IP cameras and related products contain an authentication bypass vulnerability when the loopback device is specified by the client during authentication.

CVE-2021-33045 is an authentication bypass vulnerability affecting Dahua IP camera firmware and related products. It allows an attacker who specifies the loopback device during the authentication process to bypass normal access controls. For IT and security teams, this matters because IP cameras often sit on networks with access to video feeds, configuration interfaces, and sometimes broader internal systems; successful abuse can give unauthorized control or visibility without valid credentials.

Public detail centers on the authentication path rather than broader product features. Confirm exact product lines, firmware revisions, and any related devices against the vendor advisory before treating any asset as unaffected.

How it works

The underlying weakness is CWE-287 (Improper Authentication). In normal operation, the camera or related product expects a client to present valid credentials before granting access. The flaw arises when the client specifies the loopback device as part of the authentication exchange. Under that condition, the authentication check can be bypassed, allowing the request to proceed as if it were authorized.

An attacker who can reach the authentication interface therefore has a path to gain access without supplying legitimate credentials. The CISA summary describes the trigger as the client specifying the loopback device during authentication; no further exploit mechanics are provided in the available facts. Teams should treat any unauthenticated or anomalous authentication traffic that references loopback addresses as potentially related and investigate against the vendor’s technical description.

Am I affected? How to find it in your systems

Dahua IP cameras and related products that run the affected firmware are in scope. These devices commonly appear on corporate, campus, and industrial networks for physical security monitoring, often with web or API management interfaces exposed internally or, in poorly segmented environments, more widely.

Inventory steps:

Telemetry and log signs of possible exploitation include authentication requests that reference loopback addresses or interfaces, sudden successful logins without corresponding credential entries, or unexpected configuration or stream-access activity from previously unknown sources. Correlate these events with network flow data showing connections to camera management ports. Because specific log formats are not detailed in the facts, treat any anomalous authentication success as a candidate for deeper review.

How to remediate

The primary action is to apply the mitigations or firmware updates supplied by the vendor. CISA’s required action is to apply mitigations per vendor instructions or, if mitigations are unavailable, to discontinue use of the product. Obtain the official advisory, identify the recommended update or configuration change for each affected model, and deploy it through your normal change-control process.

After patching:

Document the remediation status of every inventoried device so that residual risk can be tracked.

If you can't patch immediately

Until the vendor update can be applied, reduce the attack surface with compensating controls:

These measures do not eliminate the vulnerability; they only lower the likelihood of successful exploitation while a permanent fix is prepared.

If your data may have been exposed

Actively exploited authentication-bypass vulnerabilities can lead to unauthorized access to video streams, device configurations, or connected systems, which in turn can result in data exposure or further lateral movement. Known ransomware use of this specific CVE is not documented in the available facts. If you suspect compromise, isolate the affected devices, preserve logs, and follow your incident-response process. As a separate hygiene step, individuals can run a free exposure scan of their email addresses against known breach data sets to check whether personal credentials have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedDahua · IP Camera Firmware
WeaknessCWE-287
Added to CISA KEVAug 21, 2024
Federal patch deadlineSep 11, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities