ZeroHour
Vendor

ITRES Labs

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

Hunt.io disclosed Operation CameraSwarm, compromising 14,500+ Dahua cameras via credential attacks, auth bypass CVEs, and P2P relay techniques across Ukraine and Russia.

Hunt.io reconstructed a campaign codenamed Operation CameraSwarm that compromised over 14,530 Dahua devices between June 17 and July 22, 2026. Attack paths included credential attacks against 12,324 IPs, exploitation of CVE-2021-33044 and CVE-2021-33045 affecting 1,923 cameras, and P2P relay access to 283 devices behind NAT. The operator, assessed as Russian-speaking, left behind 2,616 files including tooling and campaign logs, with confirmed compromises concentrated in Ukraine and Russia. Dahua advises factory resets and firmware updates; both 2021 CVEs remain in CISA's KEV catalog.

The Hacker News · 21d agoThreat actor in the wildCVE-2021-33044CVE-2021-33045CVE-2024-39943+1 CVEs1

Related CVEs

  • Authentication Bypass in Dahua IP Cameras, NVRs and Video Intercoms
    Dahua IP cameras, network recorders and video-intercom devices are affected by a critical identity authentication bypass (CWE-287) in the login process. By constructing malicious data packets sent to a device during the login process, an attacker can bypass device identity authentication entirely, yielding full unauthenticated access with high impact on confidentiality, integrity and availability (CVSS 3.1: 9.8). The flaw spans a broad set of Dahua firmware, including IPC-HUM7xxx/HX3xxx/HX5xxx cameras, NVR-1xxx/2xxx/4xxx/5xxx/6xx and XVR-4x04 recorders, and the VTH-542XH, VTO-65xxx and VTO-75x95x video-intercom units. Public proof-of-concept exploits have been available since October 2021, and CISA added the bug to its Known Exploited Vulnerabilities catalog on 2024-08-21; public reporting describes 14,500+ Dahua devices compromised via credential attacks, auth bypasses and P2P abuse, and EPSS assigns a 99.6% probability of exploitation within 30 days.
    · Dahua IPC-HUM7xxx IP camera firmware · Dahua IPC-HX3xxx IP camera firmware KEV PoC ×2mass
  • Authentication Bypass in Dahua IP Camera Firmware
    Dahua IP cameras and related products contain an authentication bypass flaw (CWE-287, Improper Authentication) that is triggered when the client supplies the NetKeyboard type argument during the authentication process, allowing the device to treat the session as authenticated without valid credentials. An unauthenticated remote attacker who can reach the camera's network interface can exploit this to gain unauthorized access to the device's management functions. Successful exploitation can expose camera video streams and device configuration and can serve as a foothold into the surrounding surveillance or corporate network. Any organization running affected Dahua IP camera firmware, particularly cameras exposed to the internet, is potentially affected. The flaw is confirmed to be exploited in the wild: it was added to the CISA KEV on 2024-08-21, and EPSS assigns it a 99.9% probability of exploitation within 30 days (100th percentile), although no public PoC is known.
    · Dahua IP Camera Firmware KEV PoC ×2mass
  • rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload per
    rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions). This occurs because a shell is used to execute df (i.e., with execSync instead of spawnSync in child_process in Node.js).
    · rejetto http file server
  • A vulnerability exists in certain Dahua embedded products.
    A vulnerability exists in certain Dahua embedded products. Third-party malicious attacker with obtained normal user credentials could exploit the vulnerability to access certain data which are restricted to admin privileges, such as system-sensitive files through specific HTTP request. This may cause tampering with admin password, leading to privilege escalation. Systems with only admin account are not affected.

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.