Dahua cameras authentication-bypass vulnerabilities (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2021-33044 and CVE-2021-33045 are authentication-bypass flaws in Dahua cameras and related products that let attackers bypass device identity checks during login. Hunt.io linked the flaws to Operation CameraSwarm, which compromised more than 14,530 Dahua IP cameras between June 17 and July 22, 2026 using TCP/37777 brute-forcing, cloud-relay access, and exploitation of the CVEs to install a persistent p2pwn backdoor account on 1,923 cameras. The researchers also said 283 cameras were reached through P2P and recovered 407 MB of operator data. Dahua lists fixed firmware, and CISA KEV still tracks both issues as exploited vulnerabilities.
Cases
Related Happenings
CISA KEV guidance for Dahua IP camera authentication-bypass flaws (CVE-2021-33044, CVE-2021-33045)
Advisory/Mitigation
H score81
First: 19.08.2026 14:34
Last: 19.08.2026 14:34
Sources 1
How related:
As of August 19, 2026, both flaws remain listed in the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog, which records them as Dahua IP camera authentication-bypass vulnerabilities and advises applying vendor mitigations or discontinuing use if mitigations are unavailable.
About this happening:
CISA kept CVE-2021-33044 and CVE-2021-33045 in the KEV catalog for Dahua IP camera authentication-bypass vulnerabilities, directing defenders to apply vendor...
CISA KEV guidance for Dahua IP camera authentication-bypass flaws (CVE-2021-33044, CVE-2021-33045)
Advisory/MitigationHow related: As of August 19, 2026, both flaws remain listed in the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog, which records them as Dahua IP camera authentication-bypass vulnerabilities and advises applying vendor mitigations or discontinuing use if mitigations are unavailable.
About this happening: CISA kept CVE-2021-33044 and CVE-2021-33045 in the KEV catalog for Dahua IP camera authentication-bypass vulnerabilities, directing defenders to apply vendor...
Operation CameraSwarm campaign targeting Dahua devices
Campaign
H score70
First: 19.08.2026 14:34
Last: 19.08.2026 14:34
Sources 1
How related:
In a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and Russia.
About this happening:
Hunt.io disclosed Operation CameraSwarm, a 35-day campaign that compromised more than 14,530 Dahua IP cameras mostly in Ukraine and Russia. The operation used...
Operation CameraSwarm campaign targeting Dahua devices
CampaignHow related: In a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and Russia.
About this happening: Hunt.io disclosed Operation CameraSwarm, a 35-day campaign that compromised more than 14,530 Dahua IP cameras mostly in Ukraine and Russia. The operation used...
StormEncryptor ransomware deployment by Storm-1175
Malware Activity
H score40
First: 10.08.2026 20:42
Last: 10.08.2026 20:42
Sources 1
About this happening:
Storm-1175 is deploying StormEncryptor, a previously undocumented ransomware strain that appends .encrypted to encrypted files and drops !!!README_FIRST!!!.txt ran...
StormEncryptor ransomware deployment by Storm-1175
Malware ActivityAbout this happening: Storm-1175 is deploying StormEncryptor, a previously undocumented ransomware strain that appends .encrypted to encrypted files and drops !!!README_FIRST!!!.txt ran...
Qilin (aka Agenda) ransomware deployment after PAN-OS exploitation
Malware Activity
H score40
First: 21.07.2026 17:04
Last: 21.07.2026 17:04
Sources 1
About this happening:
Qilin (aka Agenda) ransomware was deployed across multiple June 2026 intrusions after attackers exploited CVE-2026-0257 in Palo Alto Networks PAN-OS to gain initia...
Qilin (aka Agenda) ransomware deployment after PAN-OS exploitation
Malware ActivityAbout this happening: Qilin (aka Agenda) ransomware was deployed across multiple June 2026 intrusions after attackers exploited CVE-2026-0257 in Palo Alto Networks PAN-OS to gain initia...
CERT/CC Tenda router backdoor mitigation
Advisory/Mitigation
H score31
First: 07.07.2026 09:40
Last: 07.07.2026 09:40
Sources 1
About this happening:
CERT/CC issued interim mitigation for Tenda firmware after disclosure of CVE-2026-11405, advising users to disable remote management and change the default LAN I...
CERT/CC Tenda router backdoor mitigation
Advisory/MitigationAbout this happening: CERT/CC issued interim mitigation for Tenda firmware after disclosure of CVE-2026-11405, advising users to disable remote management and change the default LAN I...
Timeline
-
19.08.2026 14:34 3 articles · 13d ago
Operation CameraSwarm uses Dahua camera authentication bypasses
Initial DisclosureHunt.io said Operation CameraSwarm compromised more than 14,530 Dahua devices between June 17 and July 22, 2026 by combining credential attacks, CVE-2021-33044, CVE-2021-33045, and a P2P relay path. The researchers said 1,923 cameras were configured with a persistent account and 283 were reached through P2P, while Dahua and CISA still track the two authentication-bypass flaws and advise installing vendor fixes or newer firmware.
Show sources
- Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P — thehackernews.com — 19.08.2026 14:34
- Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P — thehackernews.com — 19.08.2026 14:34
- Hackers compromise 14,500 Dahua web cameras in 35-day campaign — www.bleepingcomputer.com — 19.08.2026 21:09