Find notable cyber news and cases, enriched with sources, timelines, and signals.

Dahua cameras authentication-bypass vulnerabilities (multiple vulnerabilities)

Vulnerability
First reported
Last updated
Happening score
H score 78
2 unique sources, 2 articles

Summary

Hide ▲

CVE-2021-33044 and CVE-2021-33045 are authentication-bypass flaws in Dahua cameras and related products that let attackers bypass device identity checks during login. Hunt.io linked the flaws to Operation CameraSwarm, which compromised more than 14,530 Dahua IP cameras between June 17 and July 22, 2026 using TCP/37777 brute-forcing, cloud-relay access, and exploitation of the CVEs to install a persistent p2pwn backdoor account on 1,923 cameras. The researchers also said 283 cameras were reached through P2P and recovered 407 MB of operator data. Dahua lists fixed firmware, and CISA KEV still tracks both issues as exploited vulnerabilities.

Cases

Related Happenings

CISA KEV guidance for Dahua IP camera authentication-bypass flaws (CVE-2021-33044, CVE-2021-33045)

Advisory/Mitigation
H score81 First: 19.08.2026 14:34 Last: 19.08.2026 14:34 Sources 1

How related: As of August 19, 2026, both flaws remain listed in the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog, which records them as Dahua IP camera authentication-bypass vulnerabilities and advises applying vendor mitigations or discontinuing use if mitigations are unavailable.

About this happening: CISA kept CVE-2021-33044 and CVE-2021-33045 in the KEV catalog for Dahua IP camera authentication-bypass vulnerabilities, directing defenders to apply vendor...

Operation CameraSwarm campaign targeting Dahua devices

Campaign
H score70 First: 19.08.2026 14:34 Last: 19.08.2026 14:34 Sources 1

How related: In a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and Russia.

About this happening: Hunt.io disclosed Operation CameraSwarm, a 35-day campaign that compromised more than 14,530 Dahua IP cameras mostly in Ukraine and Russia. The operation used...

StormEncryptor ransomware deployment by Storm-1175

Malware Activity
H score40 First: 10.08.2026 20:42 Last: 10.08.2026 20:42 Sources 1

About this happening: Storm-1175 is deploying StormEncryptor, a previously undocumented ransomware strain that appends .encrypted to encrypted files and drops !!!README_FIRST!!!.txt ran...

Qilin (aka Agenda) ransomware deployment after PAN-OS exploitation

Malware Activity
H score40 First: 21.07.2026 17:04 Last: 21.07.2026 17:04 Sources 1

About this happening: Qilin (aka Agenda) ransomware was deployed across multiple June 2026 intrusions after attackers exploited CVE-2026-0257 in Palo Alto Networks PAN-OS to gain initia...

CERT/CC Tenda router backdoor mitigation

Advisory/Mitigation
H score31 First: 07.07.2026 09:40 Last: 07.07.2026 09:40 Sources 1

About this happening: CERT/CC issued interim mitigation for Tenda firmware after disclosure of CVE-2026-11405, advising users to disable remote management and change the default LAN I...

Timeline

  1. 19.08.2026 14:34 3 articles · 13d ago

    Operation CameraSwarm uses Dahua camera authentication bypasses

    Initial Disclosure

    Hunt.io said Operation CameraSwarm compromised more than 14,530 Dahua devices between June 17 and July 22, 2026 by combining credential attacks, CVE-2021-33044, CVE-2021-33045, and a P2P relay path. The researchers said 1,923 cameras were configured with a persistent account and 283 were reached through P2P, while Dahua and CISA still track the two authentication-bypass flaws and advise installing vendor fixes or newer firmware.

    Show sources