Cybersecurity researchers have uncovered a significant campaign that compromised more than 14,500 Dahua devices between June 17 and July 22, 2026. The attackers employed credential attacks, exploited two authentication-bypass vulnerabilities, and utilized a peer-to-peer (P2P) relay technique to gain unauthorized access.
Details of the Attack
The operation, dubbed ‘CameraSwarm,’ was reconstructed from an exposed working directory containing 2,616 files across 234 subdirectories. This repository included tools, logs, shell history, and records of the campaign. Confirmed compromises were predominantly located in Ukraine and Russia.
Analysis revealed that 1,923 cameras were configured with a persistent unauthorized account during the operation, and 283 devices were accessed through the P2P relay method.
Methods of Compromise
The attackers utilized three primary methods to infiltrate the devices:
- Credential Attacks: Targeted 12,324 unique IP addresses, resulting in 13,229 successful breaches.
- Authentication Bypass: Exploited vulnerabilities CVE-2021-33044 and CVE-2021-33045 to access 1,923 cameras, which were then configured with persistent unauthorized accounts.
- P2P Relay: Identified 283 cameras by their serial numbers, including devices located behind network address translation (NAT).
Vulnerabilities Exploited
The two authentication-bypass vulnerabilities, CVE-2021-33044 and CVE-2021-33045, were identified in Dahua cameras and related products. These flaws allow attackers to bypass device identity authentication by crafting malicious data packets. Dahua’s advisory rates these vulnerabilities with a CVSS score of 8.1 and provides information on fixed firmware versions. However, the U.S. National Vulnerability Database assigns each a CVSS score of 9.8.
Specifically, CVE-2021-33044 can be triggered during authentication by a NetKeyboard client type, while CVE-2021-33045 involves a loopback login request using the 127.0.0.1 address.
Recommendations for Users
Users of affected Dahua products are strongly advised to install the latest firmware updates provided by the vendor. Additionally, it is recommended to disable the P2P feature if it is not required and to verify firmware versions against the vendor’s official download site.
These vulnerabilities remain listed in the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities catalog. CISA advises applying vendor mitigations or discontinuing use if mitigations are unavailable.
Given the widespread impact of this campaign, it is crucial for organizations and individuals using Dahua devices to take immediate action to secure their systems. Regularly updating firmware, disabling unnecessary features, and monitoring for unauthorized access are essential steps in mitigating such threats.