The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

Project Subscriptions

Vendors Products
Dahuasecurity Subscribe
Ipc-hum7xxx Subscribe
Ipc-hum7xxx Firmware Subscribe
Ipc-hx3xxx Subscribe
Ipc-hx3xxx Firmware Subscribe
Ipc-hx5xxx Subscribe
Ipc-hx5xxx Firmware Subscribe
Nvr-1xxx Subscribe
Nvr-1xxx Firmware Subscribe
Nvr-2xxx Subscribe
Nvr-2xxx Firmware Subscribe
Nvr-4xxx Subscribe
Nvr-4xxx Firmware Subscribe
Nvr-5xxx Subscribe
Nvr-5xxx Firmware Subscribe
Nvr-6xx Subscribe
Nvr-6xx Firmware Subscribe
Vth-542xh Subscribe
Vth-542xh Firmware Subscribe
Vto-65xxx Subscribe
Vto-65xxx Firmware Subscribe
Vto-75x95x Subscribe
Vto-75x95x Firmware Subscribe
Xvr-4x04 Subscribe
Xvr-4x04 Firmware Subscribe
Xvr-4x08 Subscribe
Xvr-4x08 Firmware Subscribe
Xvr-5x04 Subscribe
Xvr-5x04 Firmware Subscribe
Xvr-5x08 Subscribe
Xvr-5x08 Firmware Subscribe
Xvr-5x16 Subscribe
Xvr-5x16 Firmware Subscribe
Xvr-7x16 Subscribe
Xvr-7x16 Firmware Subscribe
Xvr-7x32 Subscribe
Xvr-7x32 Firmware Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 22 Oct 2025 00:30:00 +0000


Tue, 21 Oct 2025 20:30:00 +0000


Tue, 21 Oct 2025 19:30:00 +0000


Wed, 30 Jul 2025 02:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.94124}

epss

{'score': 0.94092}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: dahua

Published:

Updated: 2026-01-12T19:53:51.321Z

Reserved: 2021-05-17T00:00:00.000Z

Link: CVE-2021-33045

cve-icon Vulnrichment

Updated: 2024-08-03T23:42:19.573Z

cve-icon NVD

Status : Analyzed

Published: 2021-09-15T22:15:10.687

Modified: 2026-01-13T22:20:20.110

Link: CVE-2021-33045

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses