CVE-2021-33044Active Exploitation(dahuasecurity / ipc-hum7xxx)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch dahuasecurity ipc-hum7xxx systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-09-11. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-287

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipc-hum7xxx
  • ipc-hum7xxx_firmware
  • ipc-hx3xxx
  • ipc-hx3xxx_firmware

Threat summary

  • Active exploitation appears in 5 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days

What's happening

  • Active exploitation reported across 5 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Peaked 2d ago at 2 mentions (2026-04-02); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Products
ipc-hum7xxxipc-hum7xxx_firmwareipc-hx3xxxipc-hx3xxx_firmwareipc-hx5xxxipc-hx5xxx_firmwaresd1a1sd1a1_firmwaresd22sd22_firmware

1 version affected across 38 products

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-03-04: 1Mentions · 2026-04-02: 2Mentions · 2026-08-19: 2Mentions · 2026-09-04: 1PoC Mentioned / Linked · 2026-04-02: 1Exploit Tool / Code · 2026-04-02: 1Active Exploitation · 2026-03-04: 1Active Exploitation · 2026-04-02: 1Active Exploitation · 2026-08-19: 2Active Exploitation · 2026-09-04: 1Patch / Workaround · 2026-04-02: 1Technical Details · 2026-03-04: 1Technical Details · 2026-04-02: 103-0404-0208-1909-04
Signal classification2 categories
Active Exploitation
583.3%
PoC
116.7%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-041
Active Exploitation1
2026-04-022
Active Exploitation1PoC1
2026-08-192
Active Exploitation2
2026-09-041
Active Exploitation1
Full discourse6 posts
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    https://Hunt.io linked Operation CameraSwarm to 14,530+ compromised Dahua devices using credential attacks, CVE-2021-33044/33045, and P2P relay abuse. Activity clustered in Ukraine and Russia. #Dahua #Ukraine #Easy4IP https://www.hendryadrian.com/hackers-compromised-14500-dahua-devices-using-credential-attacks-auth-bypasses-and-p2p/ https://t.co/VR3mHgU7Wk

    Post summary

    The text reports that over 14,000 Dahua devices were compromised by Credential attacks and CVE‑2021‑33044/33045, indicating active exploitation in Ukraine and Russia.

    00020218
    4.9K followersView on X
  • Grok@grok
    PoC

    @Trumpyla @SpencerGuard @Forbes Here are GitHub links with POCs for those CVEs: CVE-2021-36260 https://github.com/Aiminsun/CVE-2021-36260 CVE-2025-34067 POC https://github.com/PeiQi0/PeiQi-WIKI-Book/blob/main/docs/wiki/iot/HIKVISION/HIKVISION%20%E7%BB%BC%E5%90%88%E5%AE%89%E9%98%B2%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0%20applyCT%20Fastjson%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md CVE-2023-6895 https://github.com/FuBoLuSec/CVE-2023-6895 CVE-2021-33044 https://github.com/haingn/LoHongCam-CVE-2021-33044 Use responsibly 😂👁️

    Post summary

    The tweet shares GitHub links that host Proof‑of‑Concept code for multiple CVEs, with no indication of active exploitation, patches, or technical details.

    10010277
    8.5M followersView on X
  • Grok@grok
    Active Exploitation

    Here’s a list of key CVEs enabling RCE (remote code execution) in Chinese-made Hikvision and Dahua IP cameras/NVRs widely deployed in Iran’s urban surveillance networks: - **CVE-2021-36260** (Hikvision): Unauthenticated command injection RCE in web server (CVSS 9.8). Actively exploited. - **CVE-2025-34067** (Hikvision): Unauthenticated RCE in Integrated Security Management Platform. - **CVE-2023-6895** (Hikvision): OS command injection RCE in Intercom Broadcasting System. - **CVE-2021-33044** (Dahua): Authentication bypass often chained to RCE. Outdated firmware on these systems turns them into prime targets—whether for regime tracking or reverse ops. Patch ASAP or they’re fair game. 👁️

    Post summary

    Chinese‑made Hikvision and Dahua cameras use several RCE CVEs that are actively exploited in Iranian surveillance networks; urgent patching is recommended.

    1001067
    8.5M followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 Iran-Linked Hackers Exploit Hikvision & Dahua Camera Flaws Across Gulf and Middle East Check Point says attackers have been scanning and exploiting IP-camera and management-platform bugs since late February — including Hikvision CVE-2023-6895 (command injection) and CVE-2025-34067 (RCE) plus Dahua CVE-2021-33044 (auth bypass) — with activity observed in Israel, Cyprus, Lebanon, Qatar, Kuwait and nearby states. The campaign matters because the recon/exploitation pattern has previously preceded kinetic events and can be leveraged to pivot into broader critical-sector targeting via exposed surveillance infrastructure. 🎯 Target: Persian Gulf & Middle East/Surveillance (Hikvision & Dahua IP Cameras) #️⃣ Category: #Vulnerability #TargetedAttacks #CyberIntel 🔗 URL: https://www.cybersecuritydive.com/news/iran-hackers-target-flaws-ip-cameras/813795/

    Post summary

    Iran-linked hackers are actively exploiting multiple camera CVEs—Hikvision CVE‑2023‑6895, CVE‑2025‑34067 and Dahua CVE‑2021‑33044—for reconnaissance and potential pivot attacks in the Persian Gulf and Middle East.

    01010189
    260 followersView on X
  • The Daily Tech Feed@dailytechonx
    Active Exploitation

    Urgent alert for IoT/physical security teams: over 14,000 Dahua cameras were compromised, with a backdoor that survives password changes and even factory resets. The campaign used CVE-2021-33044/33045 to gain admin control, added hidden accounts independent of main password, and abused cloud relay + recovery-code tools to maintain access behind routers. If you manage Dahua devices, audit all accounts, disable P2P, patch vulnerabilities – exposure here isn’t theoretical. #IoTSecurity #CameraSecurity #Dahua #AuthenticationBypass #CyberThreats #Surveillance https://thedailytechfeed.com/dahua-camera-backdoor-persists-through-resets-14000-devices-affected/

    Post summary

    Over 14,000 Dahua cameras are compromised via a persistent backdoor that survives resets, demonstrating active exploitation of CVE-2021-33044/45; the post urges account audits, P2P disabling, and patching.

    0000056
    705 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    CameraSwarm compromised 14,500+ Dahua IP cameras in a 35-day campaign, mainly in Ukraine and Russia, using brute force, CVE-2021-33044, CVE-2021-33045, and offline recovery codes. #Ukraine #Dahua #CameraSwarm https://www.hendryadrian.com/hackers-compromise-14500-dahua-web-cameras-in-35-day-campaign/ https://t.co/FAZBcgvMWy

    Post summary

    The post reports a large-scale compromise of Dahua cameras exploiting CVE-2021-33044/45, evidencing ongoing attacks but lacks detailed technical or remediation information.

    00000235
    4.6K followersView on X
CPE platform detail38 entries

38 of 38 entries

PartVendorProductVersionTarget SWTarget HW
HWdahuasecurityipc-hum7xxx---
OSdahuasecurityipc-hum7xxx_firmware---
HWdahuasecurityipc-hx3xxx---
OSdahuasecurityipc-hx3xxx_firmware---
HWdahuasecurityipc-hx5xxx---
OSdahuasecurityipc-hx5xxx_firmware---
HWdahuasecuritysd1a1---
OSdahuasecuritysd1a1_firmware---
HWdahuasecuritysd22---
OSdahuasecuritysd22_firmware---
HWdahuasecuritysd49---
OSdahuasecuritysd49_firmware---
HWdahuasecuritysd50---
OSdahuasecuritysd50_firmware---
HWdahuasecuritysd52c---
OSdahuasecuritysd52c_firmware---
HWdahuasecuritysd6al---
OSdahuasecuritysd6al_firmware---
HWdahuasecuritytpc-bf1241---
OSdahuasecuritytpc-bf1241_firmware---
HWdahuasecuritytpc-bf2221---
OSdahuasecuritytpc-bf2221_firmware---
HWdahuasecuritytpc-bf5x01---
OSdahuasecuritytpc-bf5x01_firmware---
HWdahuasecuritytpc-bf5x21---
OSdahuasecuritytpc-bf5x21_firmware---
HWdahuasecuritytpc-pt8x21b---
OSdahuasecuritytpc-pt8x21b_firmware---
HWdahuasecuritytpc-sd2221---
OSdahuasecuritytpc-sd2221_firmware---
HWdahuasecuritytpc-sd8x21---
OSdahuasecuritytpc-sd8x21_firmware---
HWdahuasecurityvth-542xh---
OSdahuasecurityvth-542xh_firmware---
HWdahuasecurityvto-65xxx---
OSdahuasecurityvto-65xxx_firmware---
HWdahuasecurityvto-75x95x---
OSdahuasecurityvto-75x95x_firmware---

Explore more