CameraRisk

CVE-2021-33045

Dahua · exploited in the wild

Published
15 September 2021
Last modified
17 June 2026
CVSS
9.8 v3.1
Severity
critical
EPSS
99.6% (100th pct)
CISA KEV
Added 21 August 2024 KEV
NVD status
Analyzed
Weaknesses
CWE-287

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

Exploitation

Added to the CISA Known Exploited Vulnerabilities catalogue on 21 August 2024, with a remediation due date of 11 September 2024 for US federal civilian agencies. CISA records no known ransomware campaign use.

Required action as published by CISA: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Affected products

ProductVendorTypeVersions named
Ipc-hum7xxx Dahua IP camera < 2.820.0000000.5.r.210705
Ipc-hx3xxx Dahua IP camera < 2.800.0000000.29.r.210630, <= 2021-7, >= 2017-7
Ipc-hx5xxx Dahua IP camera < 2.820.0000000.18.r.210705, < 2.820.0000000.5.r.210705, <= 2021-7, >= 2017-7
NVR-1XXX Dahua Network video recorder < 4.001.0000005.1.r.210709
NVR-2XXX Dahua Network video recorder < 4.001.0000000.1.r.210710
NVR-4XXX Dahua Network video recorder < 4.001.0000005.1.r.210713
NVR-5XXX Dahua Network video recorder < 4.001.0000000.0.r.210710
NVR-6XX Dahua Network video recorder < 4.001.0000001.1.r.210716
VTH-542XH Dahua unknown < 4.500.0000002.0.r.210715
VTO-65XXX Dahua unknown < 4.300.0000004.0.r.210715
VTO-75X95X Dahua unknown < 4.300.0000003.0.r.210714
XVR-4X04 Dahua Digital video recorder < 4.001.0000001.1.r.210709
XVR-4X08 Dahua Digital video recorder < 4.001.0000001.1.r.210709
XVR-5X04 Dahua Digital video recorder < 4.001.0000003.1.r.210710
XVR-5X08 Dahua Digital video recorder < 4.001.0000003.1.r.210710
XVR-5X16 Dahua Digital video recorder < 4.001.0000003.1.r.210710
XVR-7X16 Dahua Digital video recorder < 4.001.0000003.1.r.210710
XVR-7X32 Dahua Digital video recorder < 4.001.0000003.1.r.210710

References

Vendor advisory and patch

CVE-2021-33045 at NVD

Record assembled from NVD, CISA KEV 2026.09.04 and FIRST EPSS 2026-09-04. Affected products are those NVD's CPE configuration names that fall inside this site's scope; a CVE may affect products outside it.