Surge in Attacks on Surveillance Cameras Linked to Iranian Hackers
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-7921 | Improper Authentication Bypass in Multiple Hikvision Products CVE-2017-7921 is an improper authentication flaw (CWE-287) in multiple Hikvision products that allows an attacker to defeat the devices' authentication checks. It is triggered by sending specially crafted requests to an affected device, causing it to treat the attacker as an authenticated user. A successful attacker gains privilege escalation on the device and access to sensitive information. Any organization running affected Hikvision products, particularly devices reachable from the internet, is affected; the source data does not specify the individual models or firmware version ranges. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-03-05, confirming exploitation in the wild (ransomware use unknown), and EPSS assigns a ~100% probability of exploitation within 30 days. Do: Upgrade affected Hikvision devices to vendor-fixed firmware per Hikvision's security advisories (the data here does not name specific fixed versions), and follow CISA's required actions or BOD 22-01 guidance if applicable. Reduce exposure by removing affected devices from direct internet access and restricting the management interface to trusted networks. Check device logs and configurations for signs of unauthenticated or unauthorized access. | 9.8 | 100% | KEV |
| mass~1,000,000+ deployed devices, with hundreds of thousands internet-exposed | |
| CVE-2021-33044 | Authentication Bypass in Dahua IP Camera Firmware Dahua IP cameras and related products contain an authentication bypass flaw (CWE-287, Improper Authentication) that is triggered when the client supplies the NetKeyboard type argument during the authentication process, allowing the device to treat the session as authenticated without valid credentials. An unauthenticated remote attacker who can reach the camera's network interface can exploit this to gain unauthorized access to the device's management functions. Successful exploitation can expose camera video streams and device configuration and can serve as a foothold into the surrounding surveillance or corporate network. Any organization running affected Dahua IP camera firmware, particularly cameras exposed to the internet, is potentially affected. The flaw is confirmed to be exploited in the wild: it was added to the CISA KEV on 2024-08-21, and EPSS assigns it a 99.9% probability of exploitation within 30 days (100th percentile), although no public PoC is known. Do: Apply the mitigations or patched firmware specified in Dahua's security advisory for CVE-2021-33044; if mitigations are unavailable, discontinue use of the product as CISA's required action directs. Inventory internet-facing Dahua cameras and related devices, restrict their login interfaces from direct internet exposure, and review authentication logs for signs of prior exploitation. Ransomware use is listed as unknown, so treat any compromised camera as a potential network foothold and rotate any credentials used on the device. | 9.8 | 100% | KEV PoC ×2 |
| massplausibly millions of installed Dahua cameras worldwide, with likely >100,000 internet-exposed Dahua devices |
Full article414 words · extracted from infosecurity-magazine.com · click to collapse
A surge in attempts to compromise internet-connected surveillance cameras across the Middle East has been identified during the ongoing regional conflict, with activity attributed to infrastructure linked to Iranian threat actors.
The targeting, which began intensifying on February 28, has affected Israel, Qatar, Bahrain, Kuwait, the UAE and Cyprus, with additional focused activity observed in parts of Lebanon on March 1.
The findings, released by Check Point Research (CPR), point to a coordinated campaign against devices manufactured by Hikvision and Dahua.
The researchers said the pattern of activity aligns with Iran's established military doctrine of using compromised cameras to support operational planning and battle damage assessment following missile strikes.
Activity Tied To Regional Escalation
According to CPR, the spike in exploitation attempts coincided with key geopolitical developments. Earlier, more targeted scanning was recorded on January 14–15, around the time Iran temporarily closed its airspace amid expectations of a possible US strike.
Subsequent waves of activity aligned with other high-profile events, including:
-
January 24 – A visit to Israel by the US Central Command commander during heightened tensions
-
Early February – Public warnings from Iranian leadership that a US strike could spark wider regional conflict
The infrastructure used in the campaign combines commercial VPN exit nodes, including Mullvad, ProtonVPN, Surfshark and NordVPN, along with virtual private servers assessed to be operated by multiple Iran-linked threat actors.
Specific Vulnerabilities Exploited
The campaign observed by CPR focused exclusively on Hikvision and Dahua products. Researchers observed scanning for known vulnerabilities, including authentication bypass and remote code execution (RCE) flaws. Patches are available for all identified issues.
Check Point examined exploitation attempts involving CVE-2021-33044 and CVE-2017-7921, traced to infrastructure attributed to Iran and active since the start of the year.
The researchers noted similar tactics during the 12-day conflict between Israel and Iran in June 2025. In one widely reported incident, a street camera facing the Weizmann Institute of Science was allegedly compromised shortly before a ballistic missile struck the site.
The report concluded that monitoring camera-targeting activity from known Iranian-linked infrastructure may offer early warning of potential follow-on kinetic operations.
To help mitigate these risks, defenders should eliminate public exposure by removing WAN access and using a VPN, while enforcing strong credentials and keeping firmware up-to-date.
Additionally, they should implement network segmentation for cameras on a dedicated VLAN and monitor for unusual login attempts and outbound connections.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/iran-attacks-surveillance-cameras/