CVE-2021-33544: high-severity vulnerability in Geutebrück E2 Series
UDP Technology/Geutebrück camera devices: command injection leading to RCE
Published · Updated
80Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 7.2epss 95%
from disclosure to weapon0 days
Published on NVDSep 13
metasploitJul 8
VulnCheck+7d
exploitation probability
95%top 1% of all CVEs
observed exploitation
yesVulnCheck
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Related CVEs — Geutebrück E2 Series
In the same product, most dangerous first.
CVE-2021-33543CRITICALUDP Technology/Geutebrück camera devices: Authentication BypassEPSS 81.3%CVE-2021-33549HIGHUDP Technology/Geutebrück camera devices: Buffer overflow in action parameter leading to RCEEPSS 66.2%CVE-2021-33554HIGHUDP Technology/Geutebrück camera devices: Command injection in appfile.filename parameter leading to RCEEPSS 57.0%CVE-2021-33550HIGHUDP Technology/Geutebrück camera devices: Command injection in date parameter leading to RCEEPSS 57.0%CVE-2021-33548HIGHUDP Technology/Geutebrück camera devices: Command injection in preserve parameter leading to RCEEPSS 57.0%CVE-2021-33553HIGHUDP Technology/Geutebrück camera devices: Command injection in command parameter leading to RCEEPSS 48.8%