Over 14,500 Dahua Cameras Hijacked via Unpatched CVEs and Weak Credentials
Operation CameraSwarm exploited two authentication-bypass vulnerabilities (CVE-2021-33044 and CVE-2021-33045) that were disclosed in 2021 — meaning thousands of devices remained unpatched for up to five years. Attackers combined these bypasses with credential stuffing, indicating that weak or default passwords compounded the exposure. The P2P relay technique allowed attackers to route through Dahua's own cloud infrastructure, bypassing traditional perimeter controls. This campaign illustrates how IoT and surveillance devices are frequently treated as 'set and forget' assets, missing the patch cycles applied to conventional IT systems — making them high-value, low-effort targets for threat actors.
Tactical Insight
Immediate actions
- Apply vendor patches for CVE-2021-33044 and CVE-2021-33045 immediately, or isolate affected Dahua devices from internet exposure until patching is complete.
- Audit all Dahua device credentials and replace default or weak passwords with strong, unique credentials enforced via a password manager or PAM solution.
- Disable Dahua P2P/cloud relay features unless strictly required, and restrict management interfaces to trusted internal IP ranges only.
Long-term improvements
- Maintain a continuously updated inventory of all IoT and OT devices, including firmware versions, to ensure no asset is excluded from patch management cycles.
- Implement network segmentation to place surveillance cameras and IoT devices on isolated VLANs with restricted lateral movement to core networks.
- Establish a formal IoT patch management policy with defined SLAs for critical CVEs (e.g., patch within 30 days of vendor release).
Detection measures
- Deploy network-based anomaly detection to flag unusual outbound P2P relay traffic or unexpected authentication attempts against camera management interfaces.
- Aggregate device logs into a SIEM and create alerts for repeated failed login attempts indicative of credential stuffing activity.
- Conduct periodic external attack surface scans to identify internet-exposed management interfaces on IoT and surveillance devices.