RULE(RULE ID:338737)

Rule General Information
Release Date: 2025-03-11
Rule Name: Dahua IP Camera Loopback Authentication Bypass Vulnerability (CVE-2021-33045)
Severity:
CVE ID:
Rule Protection Details
Description: The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
Impact: An unauthorized remote attacker can bypass authentication and gain access to the application with specially crafted requests.
Affected OS: Windows, Linux, Others
Reference: http://packetstormsecurity.com/files/164423/Dahua-Authentication-Bypass.html
http://seclists.org/fulldisclosure/2021/Oct/13
https://www.dahuasecurity.com/support/cybersecurity/details/957
http://packetstormsecurity.com/files/164423/Dahua-Authentication-Bypass.html
Solutions
Please refer to announcements or patches release by the vendor: https://www.dahuasecurity.com/support/cybersecurity/details/957