A large-scale Dahua camera campaign compromised more than 14,500 IP cameras in just 35 days, researchers have found.

The operation, named CameraSwarm, ran between June 17 and July 22. It relied on brute-force attacks, known vulnerabilities and a cloud-relay technique that could reach cameras behind network address translation, or NAT.

Researchers uncovered the campaign after finding an exposed web directory on a server used by the operator. The directory contained attack tools, logs, credentials, captured images and results from compromised devices.

The confirmed and geolocated victims were concentrated in Ukraine and Russia, with Ukraine accounting for the largest share. However, the scanning activity extended across the wider internet.

Dahua camera campaign used three attack methods

The operator compromised at least 14,530 devices through three parallel attack paths.

First, a brute-force tool scanned TCP port 37777, which Dahua cameras use for their management protocol. The system reached 12,324 unique IP addresses and captured camera snapshots after gaining access. It also sent results through Telegram and exported data for Dahua’s SMART PSS management platform.

Second, the attackers exploited CVE-2021-33044 and CVE-2021-33045. Their p2pwn tool installed a separate backdoor account on 1,923 cameras.

Researchers said the account can survive a password change. On most affected firmware versions, it may also survive a factory reset. Administrators should therefore check affected devices for the p2pwn account and remove it if present.

Third, the campaign abused a cloud-relay path to reach 283 cameras behind NAT. The attackers could begin this process with a camera serial number and SDK credentials embedded in Dahua applications.

Recovery codes created another access route

The toolkit could generate offline recovery codes using a device’s serial number. An attacker could then use Dahua’s normal password-recovery process to create new codes without knowing the current administrator password.

According to the researchers, 89.4% of live serial numbers tested by the tool returned an access channel without authentication.

The cloud relay itself does not automatically give an attacker full control over a camera. However, it can expose the management interface. Attackers could then use valid credentials or an authentication-bypass flaw to gain further access.

The researchers also found references to CVE-2024-39943 and CVE-2025-31702 in the toolkit. However, they said these identifiers do not accurately describe the observed attacks.

Owners should check exposed Dahua cameras

The researchers notified relevant national CERTs and Dahua’s product security team on August 10.

Owners should treat Dahua cameras exposed through port 37777 during the campaign period as potentially compromised. They should inspect devices for suspicious accounts and review access logs where possible.

Organisations should also disable peer-to-peer access when they do not need it. In addition, they should install Dahua’s SA-2021-0130 firmware updates for CVE-2021-33044 and CVE-2021-33045, or a later supported firmware version.

The Dahua camera campaign shows how exposed surveillance devices can become targets at scale. Closing unnecessary remote access and keeping firmware current remain essential steps for camera owners.


0 responses to “Dahua Camera Campaign Compromises 14,500 Devices”