Authentication Bypass in Dahua IP Cameras, NVRs and Video Intercoms
CISA: Dahua IP Camera Authentication Bypass Vulnerability
CVSS 3.1
9.8critical
EPSS
100%p100
Published
()
KEV added
AI analysis
Dahua IP cameras, network recorders and video-intercom devices are affected by a critical identity authentication bypass (CWE-287) in the login process. By constructing malicious data packets sent to a device during the login process, an attacker can bypass device identity authentication entirely, yielding full unauthenticated access with high impact on confidentiality, integrity and availability (CVSS 3.1: 9.8). The flaw spans a broad set of Dahua firmware, including IPC-HUM7xxx/HX3xxx/HX5xxx cameras, NVR-1xxx/2xxx/4xxx/5xxx/6xx and XVR-4x04 recorders, and the VTH-542XH, VTO-65xxx and VTO-75x95x video-intercom units. Public proof-of-concept exploits have been available since October 2021, and CISA added the bug to its Known Exploited Vulnerabilities catalog on 2024-08-21; public reporting describes 14,500+ Dahua devices compromised via credential attacks, auth bypasses and P2P abuse, and EPSS assigns a 99.6% probability of exploitation within 30 days.
What to do: Upgrade affected IPC, NVR, XVR, VTO and VTH devices to the fixed firmware listed in Dahua's security bulletin for CVE-2021-33045, or apply vendor-recommended mitigations — CISA's required action is to apply vendor mitigations or discontinue use of the product. Until patched, restrict internet exposure of device login/management interfaces and P2P connectivity, and audit affected fleets for signs of compromise (unexpected logins or P2P sessions) given the reported 14,500+ device campaign.
Affected
Dahua IPC-HUM7xxx IP camera firmware
—
Dahua IPC-HX3xxx IP camera firmware
—
Dahua IPC-HX5xxx IP camera firmware
—
Dahua NVR-1xxx network video recorder firmware
—
Dahua NVR-2xxx network video recorder firmware
—
Dahua NVR-4xxx network video recorder firmware
—
Dahua NVR-5xxx network video recorder firmware
—
Dahua NVR-6xx network video recorder firmware
—
Dahua XVR-4x04 hybrid recorder firmware
—
Dahua VTH-542XH video intercom firmware
—
Dahua VTO-65xxx video intercom firmware
—
Dahua VTO-75x95x video intercom firmware
—
Estimated exposure
masslikely millions of deployed Dahua devices globally (order-of-magnitude estimate); at least 14,500 devices confirmed compromised in recent attack campaigns — Dahua is one of the world's largest video-surveillance vendors with a device installed base in the millions, the vulnerability affects most of its camera, NVR, XVR and video-intercom product lines, and public reporting confirms 14,500+…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
CISA Known Exploited Vulnerability
Affected
Dahua IP Camera Firmware
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sysdig documents a skilled human attacker exploiting Marimo pre-auth RCE CVE-2026-39987 (CVSS 9.3), reaching an SSH bastion in eight seconds without AI tooling.
Sysdig detailed exploitation of CVE-2026-39987 (CVSS 9.3), a pre-authenticated RCE affecting all Marimo versions that came under active exploitation within hours of disclosure. A human operator used a hand-written Python script to harvest an AWS key from Secrets Manager and SSH into a bastion host in eight seconds, issuing 850+ commands over nine hours. Separately, Hunt.io disclosed an XMRig cryptomining campaign compromising 3,562 Redis servers via SLAVEOF rogue replication and AOF authorized_keys injection. Operation CameraSwarm, linked to a single operator, compromised over 14,000 Dahua IP cameras using CVE-2021-33044 and CVE-2021-33045.
Hunt.io disclosed Operation CameraSwarm, compromising 14,500+ Dahua cameras via credential attacks, auth bypass CVEs, and P2P relay techniques across Ukraine and Russia.
Hunt.io reconstructed a campaign codenamed Operation CameraSwarm that compromised over 14,530 Dahua devices between June 17 and July 22, 2026. Attack paths included credential attacks against 12,324 IPs, exploitation of CVE-2021-33044 and CVE-2021-33045 affecting 1,923 cameras, and P2P relay access to 283 devices behind NAT. The operator, assessed as Russian-speaking, left behind 2,616 files including tooling and campaign logs, with confirmed compromises concentrated in Ukraine and Russia. Dahua advises factory resets and firmware updates; both 2021 CVEs remain in CISA's KEV catalog.