VMTech
Discuss a project

Campaign Report Details Attacks on More Than 14,530 Dahua Devices

Campaign Report Details Attacks on More Than 14,530 Dahua Devices

Hunt.io has disclosed Operation CameraSwarm, a campaign it says compromised more than 14,530 Dahua devices between June 17 and July 22, 2026. The researchers reconstructed the activity from an exposed 407 MB working directory containing 2,616 files in 234 subdirectories, including tools, logs, shell history and campaign records.

Hunt.io said confirmed compromises were concentrated in Ukraine and Russia. Its analysis attributes 12,324 unique IP addresses across 13,229 records to credential attacks, 1,923 cameras to the authentication-bypass route, and 283 devices to a peer-to-peer relay path identified by serial number.

Three paths to camera access

The authentication-bypass activity involved CVE-2021-33044 and CVE-2021-33045, flaws affecting Dahua cameras and related products. Dahua rates both vulnerabilities at 8.1 under CVSS and provides fixed firmware, while the U.S. National Vulnerability Database assigns each a 9.8 score. Dahua said maliciously constructed data packets can bypass device identity authentication.

The original disclosure by researcher Bashis describes CVE-2021-33044 as being triggered by a NetKeyboard client type during authentication. CVE-2021-33045 involves a loopback login request using 127.0.0.1. Both vulnerabilities remained in CISA’s Known Exploited Vulnerabilities catalog as of August 19, 2026, with guidance to apply vendor mitigations or stop using affected products where mitigation is unavailable.

Hunt.io said the recovered operator material showed persistent accounts configured on the 1,923 cameras reached through these flaws. The public p2pwn repository independently shows tooling that accepts Dahua serial numbers, checks the two CVEs and includes a dummy-account configuration. It does not independently establish Hunt.io’s device total or its claim that the account persists after a factory reset on most firmware.

P2P relay is a separate exposure

The P2P route is distinct from the 2021 authentication bypasses. ITRES Labs found that firmware released before mid-2024 could allow someone with a valid Dahua serial number to establish an Easy4IP relay route before the device completed its own credential check. This could make a camera or network video recorder behind NAT reachable through the vendor relay infrastructure, though the device could still require authentication for access.

The dh-p2p proof of concept likewise shows the Dahua P2P protocol using Easy4IPCloud to locate a device by serial number and establish a tunnel. ITRES Labs said the serial-number relay exposure is a non-CVE issue and that the P2P path was reinforced in firmware released after mid-2024. The related actively exploited infrastructure security risks shows why organizations must treat exposed infrastructure and actively exploited weaknesses as connected operational risks.

What defenders can verify and do

Hunt.io reported that 89.4% of live serial numbers in the recovered operator data returned an open channel without authentication. That figure, as well as the campaign total, persistent-account count and P2P count, remains a campaign-specific claim that has not been independently reproduced by ITRES Labs, Dahua or a public computer emergency response team advisory.

Organizations using Dahua equipment should inventory deployed cameras and recorders, compare firmware with Dahua’s download site, and install listed repair software or newer firmware. ITRES Labs also recommends disabling P2P where it is not needed, restricting Easy4IP connectivity where appropriate, using strong unique credentials, removing unused accounts and segmenting video surveillance systems. These steps reduce avoidable exposure while teams validate their deployed devices and configurations.

#cybersecurity#iotsecurity#dahua#vulnerability
Open analytics
On the site 0 views
min read 4 19.08.2026
Instagram

Campaign Report Details Attacks on More Than 14,530 Dahua Devices

Open the post on Instagram ↗