# Operation CameraSwarm: How Attackers Claimed 14,500 Dahua Cameras Using Five-Year-Old Flaws and a Vendor's Own Relay Network
## The Threat
Between June 17 and July 22, 2026, a single threat actor quietly worked through a structured, multi-path campaign to compromise more than 14,530 Dahua IP cameras and network video recorders. Researchers at Hunt.io reconstructed the operation — which they've named Operation CameraSwarm — from an exposed 407 MB working directory the attacker left accessible: 2,616 files spread across 234 subdirectories, containing tooling, shell history, logs, and campaign records. It's a rare window into an active IoT mass-exploitation campaign, and the picture it reveals is methodical, not opportunistic.
The attacker used three distinct paths. The bulk of the volume — 12,324 unique IP addresses across 13,229 campaign records — came from straightforward credential attacks. But the more technically interesting paths exploit two authentication-bypass vulnerabilities from 2021, CVE-2021-33044 and CVE-2021-33045, both of which have sat in CISA's Known Exploited Vulnerabilities catalog for years and both of which allowed the attacker to install persistent accounts on 1,923 cameras. A third path leveraged Dahua's own Easy4IP P2P relay infrastructure to reach 283 devices sitting behind NAT — no open port required, just a valid serial number.
The geographic concentration tells its own story: confirmed compromises cluster in Ukraine and Russia, which puts surveillance infrastructure at the center of an active conflict zone directly in the crosshairs. But the techniques used here — particularly the P2P relay abuse and the factory-reset-surviving persistent account — are not geographically constrained. Any organization running unpatched Dahua hardware anywhere is exposed to the same playbook.
## Severity and Impact
| CVE | CVSS (NVD) | CVSS (Dahua) | Vector | Attack Complexity | Auth Required | CWE |
|---|---|---|---|---|---|---|
| CVE-2021-33044 | 9.8 Critical | 8.1 High | Network | Low | None | CWE-287 |
| CVE-2021-33045 | 9.8 Critical | 8.1 High | Network | Low | None | CWE-287 |
Both vulnerabilities allow an unauthenticated remote attacker to bypass device identity authentication by constructing malicious data packets. CVE-2021-33044 is triggered via a NetKeyboard client type during the authentication handshake; CVE-2021-33045 abuses a loopback login request spoofing the 127.0.0.1 address. The discrepancy between Dahua's 8.1 rating and NVD's 9.8 is notable — these are pre-auth, network-exploitable, zero-complexity flaws on internet-facing surveillance hardware. NVD's score is more defensible.
## Affected Products
Dahua's advisory covers a wide range of camera lines and NVR products. Users should cross-reference their specific hardware model and firmware version against Dahua's official download portal:
The public p2pwn and dh-p2p repositories confirm the attack tooling accepts Dahua serial numbers as input and checks both CVEs, meaning the scope of potential targets is effectively the entire installed Dahua base on older firmware.
## Mitigations
Immediate actions:
## References
---
## HackWire Analysis
The most damning detail in this story isn't the vulnerability — it's the timeline. CVE-2021-33044 and CVE-2021-33045 are five years old. They've been in the KEV catalog. Dahua published patches. And yet, in the summer of 2026, an attacker was still able to run through 14,500 devices at scale using these exact flaws. This is the IoT security debt problem in its most concrete form: a massive installed base of cameras that nobody patches, running on firmware that nobody monitors, often behind consumer routers that obscure the exposure from the owner.
The P2P relay angle deserves more attention than it's getting. Dahua's Easy4IP infrastructure is designed to make cameras accessible without port-forwarding — a genuinely useful feature for non-technical users. But ITRES Labs confirmed that on pre-mid-2024 firmware, a valid serial number was enough to establish a relay tunnel before the device performed its own credential check. The attacker recovered 89.4% of live serial numbers returning an open channel. Serial numbers are not secrets: they're printed on device labels, embedded in QR codes, and often predictable within a product run. This is vendor-provided infrastructure being weaponized against the vendor's own customers, and it's a pattern we've seen with other IoT cloud relay services.
The geographic concentration in Ukraine and Russia adds a dimension that pure security research often underplays. Compromised cameras in an active conflict zone aren't just a privacy issue — they're intelligence assets. Surveillance feeds from compromised hardware in those regions have direct military and operational value, and the timing of this campaign (June–July 2026) fits that context precisely.
For defenders in critical infrastructure, healthcare, or any organization running physical security cameras: the question isn't whether Dahua specifically is in your environment. The question is whether your camera management program treats firmware patching with the same rigor as your endpoint management. For most organizations, the honest answer is no.
— HackWire Editorial
---
## Related Coverage