7.2
CVSSv3

CVE-2021-33553

Published: 13/09/2021 Updated: 07/11/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an malicious user to remotely execute arbitrary code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

geutebrueck g-cam ebc-2110 firmware

geutebrueck g-cam ebc-2110 firmware 1.12.13.2

geutebrueck g-cam ebc-2110 firmware 1.12.14.5

geutebrueck g-cam ebc-2111 firmware

geutebrueck g-cam ebc-2111 firmware 1.12.13.2

geutebrueck g-cam ebc-2111 firmware 1.12.14.5

geutebrueck g-cam efd-2241 firmware

geutebrueck g-cam efd-2241 firmware 1.12.13.2

geutebrueck g-cam efd-2241 firmware 1.12.14.5

geutebrueck g-cam efd-2250 firmware

geutebrueck g-cam efd-2250 firmware 1.12.13.2

geutebrueck g-cam efd-2250 firmware 1.12.14.5

geutebrueck g-cam ethc-2230 firmware

geutebrueck g-cam ethc-2230 firmware 1.12.13.2

geutebrueck g-cam ethc-2230 firmware 1.12.14.5

geutebrueck g-cam ethc-2239 firmware

geutebrueck g-cam ethc-2239 firmware 1.12.13.2

geutebrueck g-cam ethc-2239 firmware 1.12.14.5

geutebrueck g-cam ethc-2240 firmware

geutebrueck g-cam ethc-2240 firmware 1.12.13.2

geutebrueck g-cam ethc-2240 firmware 1.12.14.5

geutebrueck g-cam ethc-2249 firmware

geutebrueck g-cam ethc-2249 firmware 1.12.13.2

geutebrueck g-cam ethc-2249 firmware 1.12.14.5

geutebrueck g-cam ewpc-2270 firmware

geutebrueck g-cam ewpc-2270 firmware 1.12.13.2

geutebrueck g-cam ewpc-2270 firmware 1.12.14.5

geutebrueck g-code eec-2400 firmware

geutebrueck g-code eec-2400 firmware 1.12.13.2

geutebrueck g-code eec-2400 firmware 1.12.14.5

geutebrueck g-code een-2010 firmware

geutebrueck g-code een-2010 firmware 1.12.13.2

geutebrueck g-code een-2010 firmware 1.12.14.5

geutebrueck g-code een-2040 firmware

geutebrueck g-code een-2040 firmware 1.12.13.2

geutebrueck g-code een-2040 firmware 1.12.14.5

geutebrueck g-cam ebc-2112 firmware

geutebrueck g-cam ebc-2112 firmware 1.12.13.2

geutebrueck g-cam ebc-2112 firmware 1.12.14.5

geutebrueck g-cam efd-2251 firmware

geutebrueck g-cam efd-2251 firmware 1.12.13.2

geutebrueck g-cam efd-2251 firmware 1.12.14.5

geutebrueck g-cam ewpc-2275 firmware

geutebrueck g-cam ewpc-2275 firmware 1.12.13.2

geutebrueck g-cam ewpc-2275 firmware 1.12.14.5

geutebrueck g-cam ewpc-2271 firmware

geutebrueck g-cam ewpc-2271 firmware 1.12.13.2

geutebrueck g-cam ewpc-2271 firmware 1.12.14.5

Exploits

This Metasploit module bypasses the HTTP basic authentication used to access the /uapi-cgi/ folder and exploits multiple authenticated arbitrary command execution vulnerabilities within the parameters of various pages on Geutebruck G-Cam EEC-2xxx and G-Code EBC-21xx, EFD-22xx, ETHC-22xx, and EWPC-22xx devices running firmware versions 112027 and ...