CVE-2021-33550: high-severity vulnerability in Geutebrück E2 Series
UDP Technology/Geutebrück camera devices: Command injection in date parameter leading to RCE
Published · Updated
70Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 7.2epss 57%
from disclosure to weapon0 days
Published on NVDSep 13
metasploitJul 8
VulnCheck+756d
exploitation probability
57%top 1% of all CVEs
observed exploitation
yesVulnCheck
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Related CVEs — Geutebrück E2 Series
In the same product, most dangerous first.
CVE-2021-33544HIGHUDP Technology/Geutebrück camera devices: command injection leading to RCEEPSS 95.3%CVE-2021-33543CRITICALUDP Technology/Geutebrück camera devices: Authentication BypassEPSS 81.3%CVE-2021-33549HIGHUDP Technology/Geutebrück camera devices: Buffer overflow in action parameter leading to RCEEPSS 66.2%CVE-2021-33554HIGHUDP Technology/Geutebrück camera devices: Command injection in appfile.filename parameter leading to RCEEPSS 57.0%CVE-2021-33548HIGHUDP Technology/Geutebrück camera devices: Command injection in preserve parameter leading to RCEEPSS 57.0%CVE-2021-33553HIGHUDP Technology/Geutebrück camera devices: Command injection in command parameter leading to RCEEPSS 48.8%