ZeroHour
Infosecurity Magazinepublished ()ingested Beth Maundrill

Webcams and DVRs Vulnerable to HiatusRAT, FBI Warns

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-7921
Improper Authentication Bypass in Multiple Hikvision Products

CVE-2017-7921 is an improper authentication flaw (CWE-287) in multiple Hikvision products that allows an attacker to defeat the devices' authentication checks. It is triggered by sending specially crafted requests to an affected device, causing it to treat the attacker as an authenticated user. A successful attacker gains privilege escalation on the device and access to sensitive information. Any organization running affected Hikvision products, particularly devices reachable from the internet, is affected; the source data does not specify the individual models or firmware version ranges. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-03-05, confirming exploitation in the wild (ransomware use unknown), and EPSS assigns a ~100% probability of exploitation within 30 days.

Do: Upgrade affected Hikvision devices to vendor-fixed firmware per Hikvision's security advisories (the data here does not name specific fixed versions), and follow CISA's required actions or BOD 22-01 guidance if applicable. Reduce exposure by removing affected devices from direct internet access and restricting the management interface to trusted networks. Check device logs and configurations for signs of unauthenticated or unauthorized access.

9.8100% KEV
  • Hikvision
mass~1,000,000+ deployed devices, with hundreds of thousands internet-exposed
CVE-2018-9995
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, which run re-brand

TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, which run re-branded versions of the original TBK DVR4104 and DVR4216 series, allow remote attackers to bypass authentication via a "Cookie: uid=admin" header, as demonstrated by a device.rsp?opt=user&cmd=list request that provides credentials within JSON data in a response.

NVD description · AI analysis pending
9.883% PoC ×4
  • tbkvision tbk-dvr4216 firmware
  • tbkvision tbk-dvr4104 firmware
CVE-2020-25078
Unauthenticated Admin Password Disclosure in D-Link DCS-2530L/2670L Cameras

CVE-2020-25078 is an information-disclosure flaw in the unauthenticated /config/getuser endpoint of D-Link DCS-2530L and DCS-2670L network cameras, which allows a remote, unauthenticated attacker to retrieve the device's administrator password. It is triggered simply by sending a crafted request to that HTTP endpoint over the network, with no login or user interaction required. An attacker who obtains the administrator password can log into the camera's web interface to view footage, change settings, or pivot further into the network. Owners of a DCS-2530L running firmware before 1.06.01 Hotfix or a DCS-2670L running firmware through 2.02 with the camera's web interface reachable are affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-08-05 amid active-exploitation evidence (with FBI/CISA alerts on HiatusRAT campaigns targeting webcams and DVRs), and its EPSS score of 97.9% indicates a very high near-term exploitation probability.

Do: Upgrade DCS-2530L cameras to firmware 1.06.01 Hotfix or later, and for DCS-2670L apply the latest vendor hotfix release newer than 2.02 (check D-Link's support page, as the exact fixed version is not specified in this data). Do not expose the camera web interface directly to the internet (remove port forwards/UPnP mappings or restrict access via firewall), and check device logs or perimeter traffic for unauthenticated requests to /config/getuser. Because these devices are end-of-life, plan replacement if current mitigations or firmware updates are unavailable, consistent with BOD 22-01 guidance.

7.598% KEV
  • D-Link DCS-2530L camera firmware before 1.06.01 Hotfix
  • D-Link DCS-2670L camera firmware through 2.02 (fixed version not specified in source data)
  • D-Link DCS-4603 firmware
  • +6 more
moderatelikely on the order of tens of thousands of internet-exposed camera units (estimate; no authoritative counts in source data)
CVE-2021-33044
Authentication Bypass in Dahua IP Camera Firmware

Dahua IP cameras and related products contain an authentication bypass flaw (CWE-287, Improper Authentication) that is triggered when the client supplies the NetKeyboard type argument during the authentication process, allowing the device to treat the session as authenticated without valid credentials. An unauthenticated remote attacker who can reach the camera's network interface can exploit this to gain unauthorized access to the device's management functions. Successful exploitation can expose camera video streams and device configuration and can serve as a foothold into the surrounding surveillance or corporate network. Any organization running affected Dahua IP camera firmware, particularly cameras exposed to the internet, is potentially affected. The flaw is confirmed to be exploited in the wild: it was added to the CISA KEV on 2024-08-21, and EPSS assigns it a 99.9% probability of exploitation within 30 days (100th percentile), although no public PoC is known.

Do: Apply the mitigations or patched firmware specified in Dahua's security advisory for CVE-2021-33044; if mitigations are unavailable, discontinue use of the product as CISA's required action directs. Inventory internet-facing Dahua cameras and related devices, restrict their login interfaces from direct internet exposure, and review authentication logs for signs of prior exploitation. Ransomware use is listed as unknown, so treat any compromised camera as a potential network foothold and rotate any credentials used on the device.

9.8100% KEV PoC ×2
  • Dahua IP Camera Firmware
massplausibly millions of installed Dahua cameras worldwide, with likely >100,000 internet-exposed Dahua devices
CVE-2021-36260
Unauthenticated Command Injection in Hikvision Device Web Server

CVE-2021-36260 is a command injection flaw (CWE-78) in the web server embedded in a wide range of Hikvision security camera and related devices, caused by insufficient input validation. An attacker triggers it by sending a crafted HTTP request to the device's web management interface, allowing commands to be executed on the device without authentication. Successful exploitation grants unauthenticated remote code execution on the camera or recorder, letting an attacker take control of the device, pivot into the surrounding network, or use the devices as a botnet platform. Any Hikvision device running the affected web server firmware is at risk, which includes cameras, recorders, and other surveillance hardware deployed in homes, businesses, and government facilities. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-01-10 and carries a 99.9% EPSS probability of exploitation within 30 days, while no public proof-of-concept code is cataloged in the provided data and no CVSS score has been issued yet.

Do: Apply firmware updates issued by Hikvision per the vendor's instructions, as required by CISA's KEV listing for this vulnerability. Restrict the device web management interface to trusted networks or VPN access and avoid direct internet exposure. Review web server logs for anomalous HTTP requests to the device interface and signs of command execution, and prioritize internet-facing devices for patching first.

9.8100% KEV PoC ×3
  • Hikvision Embedded web server of Hikvision security cameras and related surveillance devices
massmillions of installed devices, with roughly hundreds of thousands to over a million Hikvision web interfaces exposed to the internet
Full article355 words · extracted from infosecurity-magazine.com · click to collapse

The FBI has issued a warning that Hiatus remote access trojan (RAT) malware has been observed targeting Chinese-branded web cameras and DVRs.

Specifically, the actors have targeted Xiongmai and Hikvision devices with telnet access.

The FBI has urged limiting the use of such devices and isolating them from the networks.

In a Private Industry Notification, the Bureau warned that in March 2024, HiatusRAT actors conducted a scanning campaign targeting Internet of Things (IoT) devices in the US, Australia, Canada, New Zealand and the UK.

The latest iteration of HiatusRAT has been employed since 2022.

Cybersecurity companies have also observed these actors using the malware to target a range of Taiwan-based organizations and to carry out reconnaissance against a US government server used for submitting and retrieving defense contract proposals.

The actors scanned web cameras and DVRs for vulnerabilities including:

  • CVE-2017-7921
  • CVE-2018-9995
  • CVE-2020-25078
  • CVE-2021-33044
  • CVE-2021-36260

They also looked to exploit weak vendor-supplied passwords.

Some of the vulnerabilities currently have no security updates to address the flaws, in which case the FBI recommended users replace these systems with actively supported models.

The FBI said the perpetrators have used Ingram, a webcam-scanning tool available on Github, to conduct scanning activity.

They also used Medusa, an open-source brute-force authentication cracking tool, to target Hikvision cameras with telnet access.

Malicious cyber actors commonly use RATs to take over and control a targeted device from a distance.

The Hiatus campaign originally targeted outdated network edge devices, the FBI notice explained.

How to Protect IoT Devices

The proliferation of IoT devices has introduced new security risks and vulnerabilities to organizations.

To mitigate these risks, the FBI recommended organizations take the following steps:

  • Review or establish security policies, user agreements and patching plans
  • Patch and update operating systems, software and firmware as soon as manufacturer updates are available
  • If devices are no longer supported by the manufacturer, consider removing them from your network
  • Regularly change network system and account passwords
  • Require multifactor authentication (MFA) where possible
  • Implement security monitoring tools that log network traffic
  • Automatically update antivirus and anti-malware solutions and conduct regular virus and malware scans
  • Create offline backups of critical assets

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/webcams-vulnerable-hiatusrat-fbi/