# Operation CameraSwarm: How Attackers Claimed 14,500 Dahua Cameras Using Five-Year-Old Flaws and a Vendor's Own Relay Network


## The Threat


Between June 17 and July 22, 2026, a single threat actor quietly worked through a structured, multi-path campaign to compromise more than 14,530 Dahua IP cameras and network video recorders. Researchers at Hunt.io reconstructed the operation — which they've named Operation CameraSwarm — from an exposed 407 MB working directory the attacker left accessible: 2,616 files spread across 234 subdirectories, containing tooling, shell history, logs, and campaign records. It's a rare window into an active IoT mass-exploitation campaign, and the picture it reveals is methodical, not opportunistic.


The attacker used three distinct paths. The bulk of the volume — 12,324 unique IP addresses across 13,229 campaign records — came from straightforward credential attacks. But the more technically interesting paths exploit two authentication-bypass vulnerabilities from 2021, CVE-2021-33044 and CVE-2021-33045, both of which have sat in CISA's Known Exploited Vulnerabilities catalog for years and both of which allowed the attacker to install persistent accounts on 1,923 cameras. A third path leveraged Dahua's own Easy4IP P2P relay infrastructure to reach 283 devices sitting behind NAT — no open port required, just a valid serial number.


The geographic concentration tells its own story: confirmed compromises cluster in Ukraine and Russia, which puts surveillance infrastructure at the center of an active conflict zone directly in the crosshairs. But the techniques used here — particularly the P2P relay abuse and the factory-reset-surviving persistent account — are not geographically constrained. Any organization running unpatched Dahua hardware anywhere is exposed to the same playbook.


## Severity and Impact


| CVE | CVSS (NVD) | CVSS (Dahua) | Vector | Attack Complexity | Auth Required | CWE |

|---|---|---|---|---|---|---|

| CVE-2021-33044 | 9.8 Critical | 8.1 High | Network | Low | None | CWE-287 |

| CVE-2021-33045 | 9.8 Critical | 8.1 High | Network | Low | None | CWE-287 |


Both vulnerabilities allow an unauthenticated remote attacker to bypass device identity authentication by constructing malicious data packets. CVE-2021-33044 is triggered via a NetKeyboard client type during the authentication handshake; CVE-2021-33045 abuses a loopback login request spoofing the 127.0.0.1 address. The discrepancy between Dahua's 8.1 rating and NVD's 9.8 is notable — these are pre-auth, network-exploitable, zero-complexity flaws on internet-facing surveillance hardware. NVD's score is more defensible.


## Affected Products


Dahua's advisory covers a wide range of camera lines and NVR products. Users should cross-reference their specific hardware model and firmware version against Dahua's official download portal:


  • IP Cameras — multiple product series across consumer and enterprise lines
  • Network Video Recorders (NVRs) — affected where firmware predates Dahua's patched releases
  • Devices on firmware prior to mid-2024 — specifically vulnerable to the P2P relay path via Easy4IPCloud

  • The public p2pwn and dh-p2p repositories confirm the attack tooling accepts Dahua serial numbers as input and checks both CVEs, meaning the scope of potential targets is effectively the entire installed Dahua base on older firmware.


    ## Mitigations


    Immediate actions:


  • Apply Dahua's patched firmware — fixed firmware versions are listed on Dahua's security advisory page and download portal. This is non-negotiable for internet-facing hardware.
  • Disable P2P/Easy4IP where not required — the relay path does not require an open inbound port and works through NAT. If your deployment doesn't need remote access via Dahua's cloud relay, turn it off in the device settings.
  • Audit for persistent accounts — the campaign configured a persistent account on 1,923 cameras, and Hunt.io states this account survives a factory reset on most firmware versions. Review all user accounts after patching; do not assume a factory reset clears the compromise.
  • Rotate credentials across all Dahua devices — 12,324 IPs were hit with credential attacks, suggesting weak or default passwords remain widespread. Enforce strong, unique credentials.
  • Network segmentation — cameras should not be directly internet-exposed. Place them behind a VPN or restrict outbound access to block P2P relay establishment to Easy4IPCloud.
  • Check against CISA KEV — federal agencies are already required to remediate these CVEs. Private organizations should treat KEV listings as a prioritization signal, not background noise.

  • ## References


  • [Dahua Security Advisory — CVE-2021-33044 & CVE-2021-33045](https://www.dahuasecurity.com/support/cybersecurity/details/957)
  • [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
  • [NVD — CVE-2021-33044](https://nvd.nist.gov/vuln/detail/CVE-2021-33044)
  • [NVD — CVE-2021-33045](https://nvd.nist.gov/vuln/detail/CVE-2021-33045)
  • [Hunt.io — Operation CameraSwarm Research](https://hunt.io)
  • [ITRES Labs P2P Relay Analysis (October 2025)](https://itreslabs.com)

  • ---


    ## HackWire Analysis


    The most damning detail in this story isn't the vulnerability — it's the timeline. CVE-2021-33044 and CVE-2021-33045 are five years old. They've been in the KEV catalog. Dahua published patches. And yet, in the summer of 2026, an attacker was still able to run through 14,500 devices at scale using these exact flaws. This is the IoT security debt problem in its most concrete form: a massive installed base of cameras that nobody patches, running on firmware that nobody monitors, often behind consumer routers that obscure the exposure from the owner.


    The P2P relay angle deserves more attention than it's getting. Dahua's Easy4IP infrastructure is designed to make cameras accessible without port-forwarding — a genuinely useful feature for non-technical users. But ITRES Labs confirmed that on pre-mid-2024 firmware, a valid serial number was enough to establish a relay tunnel before the device performed its own credential check. The attacker recovered 89.4% of live serial numbers returning an open channel. Serial numbers are not secrets: they're printed on device labels, embedded in QR codes, and often predictable within a product run. This is vendor-provided infrastructure being weaponized against the vendor's own customers, and it's a pattern we've seen with other IoT cloud relay services.


    The geographic concentration in Ukraine and Russia adds a dimension that pure security research often underplays. Compromised cameras in an active conflict zone aren't just a privacy issue — they're intelligence assets. Surveillance feeds from compromised hardware in those regions have direct military and operational value, and the timing of this campaign (June–July 2026) fits that context precisely.


    For defenders in critical infrastructure, healthcare, or any organization running physical security cameras: the question isn't whether Dahua specifically is in your environment. The question is whether your camera management program treats firmware patching with the same rigor as your endpoint management. For most organizations, the honest answer is no.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)