7.2
CVSSv3

CVE-2021-33551

Published: 13/09/2021 Updated: 07/11/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an malicious user to remotely execute arbitrary code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

geutebrueck g-cam_ebc-2110_firmware

geutebrueck g-cam_ebc-2110_firmware 1.12.13.2

geutebrueck g-cam_ebc-2110_firmware 1.12.14.5

geutebrueck g-cam_ebc-2111_firmware

geutebrueck g-cam_ebc-2111_firmware 1.12.13.2

geutebrueck g-cam_ebc-2111_firmware 1.12.14.5

geutebrueck g-cam_efd-2241_firmware

geutebrueck g-cam_efd-2241_firmware 1.12.13.2

geutebrueck g-cam_efd-2241_firmware 1.12.14.5

geutebrueck g-cam_efd-2250_firmware

geutebrueck g-cam_efd-2250_firmware 1.12.13.2

geutebrueck g-cam_efd-2250_firmware 1.12.14.5

geutebrueck g-cam_ethc-2230_firmware

geutebrueck g-cam_ethc-2230_firmware 1.12.13.2

geutebrueck g-cam_ethc-2230_firmware 1.12.14.5

geutebrueck g-cam_ethc-2239_firmware

geutebrueck g-cam_ethc-2239_firmware 1.12.13.2

geutebrueck g-cam_ethc-2239_firmware 1.12.14.5

geutebrueck g-cam_ethc-2240_firmware

geutebrueck g-cam_ethc-2240_firmware 1.12.13.2

geutebrueck g-cam_ethc-2240_firmware 1.12.14.5

geutebrueck g-cam_ethc-2249_firmware

geutebrueck g-cam_ethc-2249_firmware 1.12.13.2

geutebrueck g-cam_ethc-2249_firmware 1.12.14.5

geutebrueck g-cam_ewpc-2270_firmware

geutebrueck g-cam_ewpc-2270_firmware 1.12.13.2

geutebrueck g-cam_ewpc-2270_firmware 1.12.14.5

geutebrueck g-code_eec-2400_firmware

geutebrueck g-code_eec-2400_firmware 1.12.13.2

geutebrueck g-code_eec-2400_firmware 1.12.14.5

geutebrueck g-code_een-2010_firmware

geutebrueck g-code_een-2010_firmware 1.12.13.2

geutebrueck g-code_een-2010_firmware 1.12.14.5

geutebrueck g-code_een-2040_firmware

geutebrueck g-code_een-2040_firmware 1.12.13.2

geutebrueck g-code_een-2040_firmware 1.12.14.5

geutebrueck g-cam_ebc-2112_firmware

geutebrueck g-cam_ebc-2112_firmware 1.12.13.2

geutebrueck g-cam_ebc-2112_firmware 1.12.14.5

geutebrueck g-cam_efd-2251_firmware

geutebrueck g-cam_efd-2251_firmware 1.12.13.2

geutebrueck g-cam_efd-2251_firmware 1.12.14.5

geutebrueck g-cam_ewpc-2275_firmware

geutebrueck g-cam_ewpc-2275_firmware 1.12.13.2

geutebrueck g-cam_ewpc-2275_firmware 1.12.14.5

geutebrueck g-cam_ewpc-2271_firmware

geutebrueck g-cam_ewpc-2271_firmware 1.12.13.2

geutebrueck g-cam_ewpc-2271_firmware 1.12.14.5

Exploits

This Metasploit module bypasses the HTTP basic authentication used to access the /uapi-cgi/ folder and exploits multiple authenticated arbitrary command execution vulnerabilities within the parameters of various pages on Geutebruck G-Cam EEC-2xxx and G-Code EBC-21xx, EFD-22xx, ETHC-22xx, and EWPC-22xx devices running firmware versions 112027 and ...