Dahua Cameras Compromised: 14,500 Devices Hijacked via Three Critical Vulnerabilities
In a 35‑day campaign dubbed CameraSwarm, attackers breached over 14,500 Dahua IP cameras using default‑exposed port 37777, exploiting CVE‑2021‑33044/45 with a persistent p2pwn backdoor, and leveraging a cloud SDK design flaw to gain unauthenticated remote access, especially targeting Ukraine and Russia.
1. Who Is Dahua? Event Background
Dahua Technology is the world’s second‑largest video surveillance equipment maker, offering IP cameras, NVRs, and network recording systems with annual revenue exceeding 30 billion RMB. The compromised cameras expose the default TCP port 37777 to the Internet, allowing direct scanning when firewalls are not configured.
2. CameraSwarm: 35 Days, Three Attack Paths
According to Hunt.io, attackers operated from 2026‑06‑17 to 2026‑07‑22, employing three concurrent vectors:
Path 1 – Brute‑Force (12,324 devices) : Global scans of port 37777 used automated tools to try default or weak credentials. Successful logins captured live video streams and forwarded them to a Telegram channel, accounting for roughly 85 % of the compromised devices.
Path 2 – Firmware Exploit (1,923 devices) : Known vulnerabilities CVE‑2021‑33044 and CVE‑2021‑33045 were exploited with a tool called p2pwn, which planted a persistent backdoor (username p2pwn, password p2password). The backdoor survives password changes and even factory resets, indicating a flaw deep in the boot chain.
Path 3 – Cloud Relay Attack (283 devices) : For cameras behind NAT, attackers used only the device serial number and a hard‑coded SDK credential embedded in Dahua’s cloud application to establish a remote access tunnel via Dahua’s cloud service. About 89.4 % of exposed serial numbers allowed unauthenticated tunnel creation.
3. Geopolitical Signals: Why Ukraine and Russia?
The attackers focused on Russian and CIS telecom IP ranges, with Russian‑language comments found in modified tool code, suggesting a deliberate targeting of Russian‑speaking networks. Dahua cameras are widely deployed on Ukrainian front‑line infrastructure, so compromised video feeds could be repurposed for battlefield intelligence, elevating the incident from ordinary cybercrime to a potential intelligence‑gathering operation.
4. Technical Analysis of the Three Critical Vulnerabilities
Port Exposure : The default management port 37777 is open without authentication, enabling large‑scale brute‑force attacks. Many deployments never change the port or apply firewall rules.
Persistent Backdoor : The p2pwn backdoor bypasses password resets and factory restores, indicating the flaw resides in the boot chain and cannot be fixed by a simple software patch; hardware‑level remediation is required.
Cloud SDK Design Flaw : The serial number serves as the sole credential for cloud access, and the SDK credential is hard‑coded in the application. Any attacker who obtains a serial number can bypass local passwords and directly access the camera, effectively outsourcing security to an uncontrolled public cloud environment.
5. Impact on Chinese Export‑Focused Surveillance Vendors
Increased Compliance Pressure in Western Markets : The FCC (US) and ENISA (EU) have been scrutinizing Chinese video‑surveillance gear for national‑security risks. This large‑scale breach reinforces the narrative that "Chinese devices equal security risk," giving competitors such as Axis, Avigilon, and Hanwha a marketing advantage.
Rising Brand‑Repair Costs : Dahua must improve its global PSIRT processes, vulnerability disclosure transparency, and firmware‑update frequency to restore customer confidence. The cost of switching suppliers is now lower than the trust cost of staying with a compromised vendor.
Geopolitical Premium : Deployments in sensitive regions already attract scrutiny; the incident may be portrayed as intentional facilitation of hostile actors, even though no evidence currently supports that claim.
6. Mitigation Recommendations
Hunt.io advises organizations that have deployed Dahua cameras to:
Immediately check for and remove any "p2pwn" accounts.
Disable unnecessary P2P functions and isolate cameras on an internal network.
Apply Dahua firmware SA‑2021‑0130 to patch CVE‑2021‑33044 and CVE‑2021‑33045.
Place management ports such as 37777 behind a firewall to block direct Internet access.
Note that removing the backdoor does not invalidate already‑generated recovery codes; Dahua must change the server‑side key‑derivation logic to fully close this path.
Copyright notice: Original article by HuaMeng Net, images sourced from BleepingComputer/Hunt.io for reporting purposes.
Signed-in readers can open the original source through BestHub's protected redirect.
This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactand we will review it promptly.
Black & White Path
We are the beacon of the cyber world, a stepping stone on the road to security.
How this landed with the community
Was this worth your time?
0 Comments
Thoughtful readers leave field notes, pushback, and hard-won operational detail here.
