VMTech
Discuss a project →

Campaign Report Details Attacks on More Than 14,530 Dahua Devices

Campaign Report Details Attacks on More Than 14,530 Dahua Devices

Hunt.io has disclosed Operation CameraSwarm, a campaign it says compromised more than 14,530 Dahua devices between June 17 and July 22, 2026. The researchers reconstructed the activity from an exposed 407 MB working directory containing 2,616 files in 234 subdirectories, including tools, logs, shell history and campaign records.

Hunt.io said confirmed compromises were concentrated in Ukraine and Russia. Its analysis attributes 12,324 unique IP addresses across 13,229 records to credential attacks, 1,923 cameras to the authentication-bypass route, and 283 devices to a peer-to-peer relay path identified by serial number.

Three paths to camera access

The authentication-bypass activity involved CVE-2021-33044 and CVE-2021-33045, flaws affecting Dahua cameras and related products. Dahua rates both vulnerabilities at 8.1 under CVSS and provides fixed firmware, while the U.S. National Vulnerability Database assigns each a 9.8 score. Dahua said maliciously constructed data packets can bypass device identity authentication.

The original disclosure by researcher Bashis describes CVE-2021-33044 as being triggered by a NetKeyboard client type during authentication. CVE-2021-33045 involves a loopback login request using 127.0.0.1. Both vulnerabilities remained in CISA’s Known Exploited Vulnerabilities catalog as of August 19, 2026, with guidance to apply vendor mitigations or stop using affected products where mitigation is unavailable.

Hunt.io said the recovered operator material showed persistent accounts configured on the 1,923 cameras reached through these flaws. The public p2pwn repository independently shows tooling that accepts Dahua serial numbers, checks the two CVEs and includes a dummy-account configuration. It does not independently establish Hunt.io’s device total or its claim that the account persists after a factory reset on most firmware.

P2P relay is a separate exposure

The P2P route is distinct from the 2021 authentication bypasses. ITRES Labs found that firmware released before mid-2024 could allow someone with a valid Dahua serial number to establish an Easy4IP relay route before the device completed its own credential check. This could make a camera or network video recorder behind NAT reachable through the vendor relay infrastructure, though the device could still require authentication for access.

The dh-p2p proof of concept likewise shows the Dahua P2P protocol using Easy4IPCloud to locate a device by serial number and establish a tunnel. ITRES Labs said the serial-number relay exposure is a non-CVE issue and that the P2P path was reinforced in firmware released after mid-2024. The related actively exploited infrastructure security risks shows why organizations must treat exposed infrastructure and actively exploited weaknesses as connected operational risks.

What defenders can verify and do

Hunt.io reported that 89.4% of live serial numbers in the recovered operator data returned an open channel without authentication. That figure, as well as the campaign total, persistent-account count and P2P count, remains a campaign-specific claim that has not been independently reproduced by ITRES Labs, Dahua or a public computer emergency response team advisory.

Organizations using Dahua equipment should inventory deployed cameras and recorders, compare firmware with Dahua’s download site, and install listed repair software or newer firmware. ITRES Labs also recommends disabling P2P where it is not needed, restricting Easy4IP connectivity where appropriate, using strong unique credentials, removing unused accounts and segmenting video surveillance systems. These steps reduce avoidable exposure while teams validate their deployed devices and configurations.

#cybersecurity#iotsecurity#dahua#vulnerability

CameraSwarm: What Dahua Device Owners Should Check

CameraSwarm is the name given to the reported campaign, not a Dahua product or a single vulnerability. The available analysis describes three different access paths, so defenders should assess credentials, firmware and P2P exposure separately.

Separate established risks from campaign claims

The authentication-bypass flaws CVE-2021-33044 and CVE-2021-33045 are documented vulnerabilities with fixed firmware available. The separate P2P relay issue concerns how devices could be reached through Easy4IP using a valid serial number. By contrast, the reported device totals, persistent-account findings and campaign success rates remain specific to Hunt.io’s recovered operator data and were not independently reproduced by the other parties discussed in the report.

  • Treat credential attacks, authentication bypass and P2P relay exposure as separate risks.
  • Do not interpret the reported campaign total as a count of every vulnerable Dahua device.
  • A reachable P2P tunnel does not by itself prove authenticated access to a device.

Practical CameraSwarm review checklist

Begin with an inventory of cameras and network video recorders, including model, firmware version, serial number, network location and whether P2P access is enabled. Compare deployed firmware with Dahua’s available updates, then review accounts and network controls before testing external exposure.

  • Install the applicable repair software or newer firmware listed for each device model.
  • Disable P2P where remote relay access is not operationally required.
  • Use strong, unique credentials and remove unknown, default or unused accounts.
  • Place surveillance equipment on a segmented network with restricted access.
  • Review logs and configuration changes for unexpected access or newly created accounts.

Frequently asked questions

What is CameraSwarm?

CameraSwarm is the name Hunt.io used for a reported campaign targeting Dahua cameras and related devices through credential attacks, authentication-bypass vulnerabilities and a separate P2P relay path.

Is CameraSwarm a new Dahua vulnerability?

No. The report combines several access methods. Two cited authentication-bypass flaws date from 2021, while the Easy4IP P2P relay exposure is described as a separate non-CVE issue.

What should Dahua device owners check first?

Identify deployed models and firmware, verify available updates, review user accounts, determine whether P2P is necessary and confirm that surveillance devices are isolated from sensitive business systems.

Open analytics
On the site 115 views
min read 4 19.08.2026
On Instagram 1 views
On Instagram 1 reach
Instagram

Campaign Report Details Attacks on More Than 14,530 Dahua Devices

Open the post on Instagram ↗