.. / CVE-2021-33044

Exploit for Dahua IPC/VTH/VTO - Authentication Bypass (CVE-2021-33044)

Description:

Some Dahua products contain an authentication bypass during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

Nuclei Template

View the template here CVE-2021-33044.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-33044.yaml
Copy

References:

https://seclists.org/fulldisclosure/2021/Oct/13
https://github.com/dorkerdevil/CVE-2021-33044
https://nvd.nist.gov/vuln/detail/CVE-2021-33044
https://www.dahuasecurity.com/support/cybersecurity/details/957
https://github.com/bp2008/DahuaLoginBypass