August 21, 2024 · Applied Cybernetics Group
CVE-2021-33045 — Dahua IP Camera Firmware
Dahua IP Camera Authentication Bypass Vulnerability
- Added to KEV
2024-08-21- Federal due date
2024-09-11- Vendor
- Dahua
- Product
- IP Camera Firmware
- EPSS
- 99.9th percentile (score 0.942, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2021-33045
CISA short description
Dahua IP cameras and related products contain an authentication bypass vulnerability when the loopback device is specified by the client during authentication.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.