CPATH-2026-0030 · General IoT

Dahua IP camera / VTH / VTO authentication bypass (CVE-2021-33044)

Two or more co-dominant consequence paths connect the public security record to a provisional EMERGENCY consequence band.

Candidate bandEMERGENCY
Co-dominant pathsDevice-control safety + Account authority

These paths are co-dominant because each reaches the record's highest candidate band, EMERGENCY; no array-order tie-break is applied.

Causal model

What has to happen for this consequence to hold?

3 candidate paths · explicit source, inference, and assumption boundaries.

Safety · Co-dominant path

Device-control safety

On door-station models, administrator access can release a door or disable monitoring, enabling unauthorized entry and reducing site safety.

EMERGENCY
  1. accessSource-backed

    Network-reachable without prior access

    The Dahua login service is reachable over the network, and exposed installations can be approached without an existing session.

    EvidenceNVD

  2. boundaryModel inference

    Cross-domain authority chain

    The bypass crosses from a network login into device administration and then into a physical access-control function.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Credible safety consequence

    On door-station models, administrator access can release a door or disable monitoring, enabling unauthorized entry and reducing site safety.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Device-control safety

    On door-station models, administrator access can release a door or disable monitoring, enabling unauthorized entry and reducing site safety.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Coordinated operational recovery

    Affected devices need patched firmware plus a reset and configuration review where unauthorized access may have occurred.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

The Dahua login service is reachable over the network, and exposed installations can be approached without an existing session.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

A single crafted authentication packet can open an administrator session without valid credentials.

Source-backedNVD
ExposureEX 4
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 3
Credible safety consequence

On door-station models, administrator access can release a door or disable monitoring, enabling unauthorized entry and reducing site safety.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

The administrator session exposes access-control state, device configuration, and connected surveillance data.

Model inference
AuthorityAT 3
Administrative or command authority

The bypass grants administrator command authority over door and monitoring functions, but not a vendor firmware-signing key.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

The bypass crosses from a network login into device administration and then into a physical access-control function.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

The same authentication flaw is present across affected Dahua camera, indoor-monitor, and door-station models.

Operational assumption
Execution scaleSX 4
Remote fleet-scale execution

The crafted packet can be repeated remotely against exposed door stations without visiting each installation.

Operational assumption
Recovery burdenOR 3
Coordinated operational recovery

Affected devices need patched firmware plus a reset and configuration review where unauthorized access may have occurred.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. Systemic uplift

    The CRITICAL base band rises to EMERGENCY because the remotely reusable bypass applies across affected cameras and door stations, while recovery requires coordinated deployment work.

  3. Final candidate bandEMERGENCY
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:4/EX:4/PH:3/DP:3/AT:3/CH:4/SR:4/SX:4/OR:3/EV:2/LS:PATCH_AVAILABLERead the scoring method →

Authority · Co-dominant path

Account authority

The bypass grants administrator and service authority to change configuration and issue device commands, but not signing-root control.

EMERGENCY
  1. accessSource-backed

    Network-reachable without prior access

    The affected Dahua login port is reachable over the network and can be exposed to the internet.

    EvidenceNVD

  2. boundaryModel inference

    Cross-domain authority chain

    Administrator access links the network login surface to device configuration, surveillance feeds, and connected physical functions.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Administrative or command authority

    The bypass grants administrator and service authority to change configuration and issue device commands, but not signing-root control.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Account authority

    The bypass grants administrator and service authority to change configuration and issue device commands, but not signing-root control.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Coordinated operational recovery

    Recovery requires patched firmware, reset or credential rotation, and verification of configuration across affected installations.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

The affected Dahua login port is reachable over the network and can be exposed to the internet.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

Public proof-of-concept templates send one crafted packet and do not require a password.

Source-backedNVD
ExposureEX 4
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 3
Credible safety consequence

Administrator takeover can disable monitoring or access-control functions, although this path records authority rather than a specific physical event.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

The administrator session exposes firmware, configuration, credentials, video, audio, and operational state.

Model inference
AuthorityAT 3
Administrative or command authority

The bypass grants administrator and service authority to change configuration and issue device commands, but not signing-root control.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

Administrator access links the network login surface to device configuration, surveillance feeds, and connected physical functions.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

One bypass technique applies across a large set of Dahua models that share the vulnerable authentication logic.

Operational assumption
Execution scaleSX 4
Remote fleet-scale execution

Network scanning and public templates allow remote repetition across exposed devices without per-device physical access.

Operational assumption
Recovery burdenOR 3
Coordinated operational recovery

Recovery requires patched firmware, reset or credential rotation, and verification of configuration across affected installations.

Operational assumption
Confidence and status
Evidence strengthEV 4
Field-confirmed evidence

NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. Systemic uplift

    The CRITICAL base band rises to EMERGENCY because the same remote administrator bypass can be reused across affected devices and requires coordinated credential, configuration, and firmware recovery.

  3. Final candidate bandEMERGENCY
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:4/EC:4/EX:4/PH:3/DP:3/AT:3/CH:4/SR:4/SX:4/OR:3/EV:4/LS:PATCH_AVAILABLERead the scoring method →

Privacy · Supporting path

Perception privacy

The exposed live video and audio reveal intimate, continuous perception of people and spaces around the device.

CRITICAL
  1. accessSource-backed

    Network-reachable without prior access

    A remotely reachable Dahua login service can be opened with the same authentication-bypass packet.

    EvidenceNVD

  2. boundaryModel inference

    Reusable multi-stage bridge

    The login bypass crosses the device boundary and delivers live camera or audio output to an unauthorized remote observer.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Safety-driving perception or intimate data

    The exposed live video and audio reveal intimate, continuous perception of people and spaces around the device.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Perception privacy

    The exposed live video and audio reveal intimate, continuous perception of people and spaces around the device.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Coordinated operational recovery

    Devices need the firmware fix and a reset or session review to restore confidence in feed access.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

A remotely reachable Dahua login service can be opened with the same authentication-bypass packet.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

After the one-packet bypass, viewing a camera or microphone feed uses ordinary administrator functions.

Source-backedNVD
ExposureEX 4
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 1
Minor physical effect

Viewing a feed is a surveillance and privacy harm; it does not itself actuate a door or create direct injury.

Model inference
Data / perceptionDP 4
Safety-driving perception or intimate data

The exposed live video and audio reveal intimate, continuous perception of people and spaces around the device.

Model inference
AuthorityAT 2
Bounded function authority

This path uses the compromised session to view monitoring feeds; broader administrator commands are assessed separately.

Model inference
Scale and recovery
ChainabilityCH 3
Reusable multi-stage bridge

The login bypass crosses the device boundary and delivers live camera or audio output to an unauthorized remote observer.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

The same bypass and feed-access workflow can be reused across affected Dahua models.

Operational assumption
Execution scaleSX 4
Remote fleet-scale execution

An attacker can repeat feed access across internet-exposed devices without approaching each camera.

Operational assumption
Recovery burdenOR 3
Coordinated operational recovery

Devices need the firmware fix and a reset or session review to restore confidence in feed access.

Operational assumption
Confidence and status
Evidence strengthEV 4
Field-confirmed evidence

NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. The exposed live video and audio reveal intimate, continuous perception of people and spaces around the device.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:4/EC:4/EX:4/PH:1/DP:4/AT:2/CH:3/SR:4/SX:4/OR:3/EV:4/LS:PATCH_AVAILABLERead the scoring method →

Triage implication

Verify the safety transition before acting on the band.

Validate the deployment-specific transition from digital control or perception to physical action before setting remediation urgency.

Evidence ledger

Public sources used by this record.

Every named source includes a public link. Path review remains separate from citation coverage.

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipPaths model is higher
Baseline confidencehigh
Scored2026-06-03
v3.1 · 9.8 CRITICALNVD / CNA via NVD (CVE-2021-33044)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
v3.1 · 9.8 CRITICALNVD / CNA via NVD (CVE-2021-33045)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

Assessment

CFSE Consequence Paths assesses Dahua IP camera / VTH / VTO authentication bypass (CVE-2021-33044) at EMERGENCY — the worst of 3 risk paths (safety, authority, perception). The dominant consequence is influence over a safety-relevant actuation.

Vulnerability

Dahua IP camera / VTH / VTO authentication bypass (CVE-2021-33044). Reported attack vector: Network (remote, unauthenticated crafted login packet).

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

DEVICE_CONTROL_SAFETYEMERGENCY

CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:4/EX:4/PH:3/DP:3/AT:3/CH:4/SR:4/SX:4/OR:3/EV:2/LS:PATCH_AVAILABLE

Exposure EX=4 (reachability and complexity-bound) · bands PH=CRITICAL · DP=CRITICAL · AT=CRITICAL → base CRITICAL · uplift active exploitation, fleet-reachable authority → assessed EMERGENCY.

  • On affected VTO door stations/intercoms, admin control can drive door-release / building access functions and disable surveillance, yielding physical-security impact. RE:4 network-reachable login. EC:4 single crafted packet. AT:3 admin authority over device functions including actuation/config (not trust-root). PH:3 unauthorized door release and disabled monitoring reduce physical-security safety margin enabling unauthorized building entry; not credible direct bodily injury so not 4. DP:3 access-control/op-state.
  • perception_feeds_action — true: suppressing surveillance and controlling access manipulates the security-relevant reality humans act on. CH:4 cross-domain network->device->physical access-control bridge. SR:4 reusable bypass across door-station models. SX:4 fleet-scale remote reach to any exposed VTO. OR:3 patch plus reset. EV:2 report/model-backed for the door-release physical path specifically (the CVE is field-confirmed for takeover, but VTO door-release impact is product-line-inferred rather than separately field-demonstrated);
  • active_exploitation — false for this specific physical-control consequence.

ACCOUNT_AUTHORITYEMERGENCY

CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:4/EC:4/EX:4/PH:3/DP:3/AT:3/CH:4/SR:4/SX:4/OR:3/EV:4/LS:PATCH_AVAILABLE

Exposure EX=4 (reachability and complexity-bound) · bands PH=CRITICAL · DP=CRITICAL · AT=CRITICAL → base CRITICAL · uplift active exploitation, fleet-reachable authority → assessed EMERGENCY.

Unauthenticated remote crafted login packet with the NetKeyboard type argument fully bypasses auth and grants admin-equivalent device access. RE:4 internet/network-reachable login port, AV:N. EC:4 single crafted packet, no creds, public PoCs/Nuclei templates. AT:3 admin/service authority to change config and issue commands (not a signing/OTA root, so not 4). DP:3 admin access exposes firmware/config/sensitive op-state. CH:4 reusable cross-domain bridge: app/network -> device admin -> config/feed/physical, and same technique pivots botnet enrollment. SR:4 single technique reusable across a large multi-model fleet (shared bypass logic). SX:4 fleet/internet-wide remote exploitation without per-device access; mass-scanned. OR:3 firmware update plus reset/credential rotation, no fleet signing-root rotation. EV:4 field-confirmed, CISA KEV exploited in the wild.

PERCEPTION_PRIVACYCRITICAL

CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:4/EC:4/EX:4/PH:3/DP:4/AT:2/CH:3/SR:4/SX:4/OR:3/EV:4/LS:PATCH_AVAILABLE

Exposure EX=4 (reachability and complexity-bound) · bands PH=CRITICAL · DP=CRITICAL · AT=CRITICAL → base CRITICAL · uplift active exploitation · caps privacy-only cap → assessed CRITICAL.

  • Post-bypass the attacker accesses live and recorded video/audio from cameras/VTH/VTO and can suppress monitoring. RE:4 network-reachable. EC:4 trivial once positioned (same single-packet bypass). AT:2 bounded to feed/monitoring access from the device session. PH:1 nuisance privacy intrusion, no direct injury. DP:4 live-camera and audio perception state (surveillance feed).
  • perception_feeds_action — false: the video is human-monitoring/recording, not driving an automated physical/safety actuation loop here. CH:3 crosses device->observer/cloud boundary, enables stalking/recon. SR:4 reusable across the fleet. SX:4 internet-wide mass access without per-device physical reach. OR:3 firmware patch and device reset. EV:4 field-confirmed KEV.

Published baseline

  • v3.1 9.8 CRITICAL — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — NVD / CNA via NVD (CVE-2021-33044)
  • v3.1 9.8 CRITICAL — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — NVD / CNA via NVD (CVE-2021-33045)

The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.

Sources

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0030 (“Dahua IP camera / VTH / VTO authentication bypass (CVE-2021-33044)”), paths.cfse.ai/CPATH-2026-0030 (published 2026-06-03).