Operation CameraSwarm campaign targeting Dahua devices
Campaign
Summary
Hide ▲
Show ▼
Hunt.io disclosed Operation CameraSwarm, a 35-day campaign that compromised more than 14,530 Dahua IP cameras mostly in Ukraine and Russia. The operation used TCP/37777 brute-forcing, CVE-2021-33044, CVE-2021-33045, and a cloud-relay path that relied on serial numbers and SDK credentials to reach 283 cameras behind NAT. Hunt.io also reported 1,923 cameras were configured with a persistent p2pwn account, recovered 407 MB of operator data, and said some toolkit references to CVE-2024-39943 and CVE-2025-31702 were misleading and not part of the observed attacks. Owners of affected Dahua devices were advised to check for p2pwn, disable P2P when not needed, and apply Dahua SA-2021-0130 firmware updates or later versions.
Cases
Related Happenings
Dahua cameras authentication-bypass vulnerabilities (multiple vulnerabilities)
Vulnerability
H score78
First: 19.08.2026 14:34
Last: 19.08.2026 14:34
Sources 1
How related:
Exploiting CVE-2021-33044 and CVE-2021-33045 vulnerabilities using a tool called p2pwn that installed a persistent backdoor account (p2pwn / p2password) on 1,923 cameras.
About this happening:
CVE-2021-33044 and CVE-2021-33045 are authentication-bypass flaws in Dahua cameras and related products that let attackers bypass device identity checks during log...
Dahua cameras authentication-bypass vulnerabilities (multiple vulnerabilities)
VulnerabilityHow related: Exploiting CVE-2021-33044 and CVE-2021-33045 vulnerabilities using a tool called p2pwn that installed a persistent backdoor account (p2pwn / p2password) on 1,923 cameras.
About this happening: CVE-2021-33044 and CVE-2021-33045 are authentication-bypass flaws in Dahua cameras and related products that let attackers bypass device identity checks during log...
CISA KEV guidance for Dahua IP camera authentication-bypass flaws (CVE-2021-33044, CVE-2021-33045)
Advisory/Mitigation
H score81
First: 19.08.2026 14:34
Last: 19.08.2026 14:34
Sources 1
How related:
As of August 19, 2026, both flaws remain listed in the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog, which records them as Dahua IP camera authentication-bypass vulnerabilities and advises applying vendor mitigations or discontinuing use if mitigations are unavailable.
About this happening:
CISA kept CVE-2021-33044 and CVE-2021-33045 in the KEV catalog for Dahua IP camera authentication-bypass vulnerabilities, directing defenders to apply vendor...
CISA KEV guidance for Dahua IP camera authentication-bypass flaws (CVE-2021-33044, CVE-2021-33045)
Advisory/MitigationHow related: As of August 19, 2026, both flaws remain listed in the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog, which records them as Dahua IP camera authentication-bypass vulnerabilities and advises applying vendor mitigations or discontinuing use if mitigations are unavailable.
About this happening: CISA kept CVE-2021-33044 and CVE-2021-33045 in the KEV catalog for Dahua IP camera authentication-bypass vulnerabilities, directing defenders to apply vendor...
CISA warning on FortiBleed for FortiGate customers
Public Sector Action
H score89
First: 19.06.2026 17:00
Last: 19.06.2026 17:00
Sources 1
About this happening:
CISA warned Fortinet customers with FortiGate appliances to secure exposed systems against ongoing malicious activity tied to FortiBleed. The activity had reached...
CISA warning on FortiBleed for FortiGate customers
Public Sector ActionAbout this happening: CISA warned Fortinet customers with FortiGate appliances to secure exposed systems against ongoing malicious activity tied to FortiBleed. The activity had reached...
Iran-linked Hikvision and Dahua surveillance camera targeting campaign
Campaign
H score37
First: 04.03.2026 17:00
Last: 04.03.2026 17:00
Sources 1
About this happening:
A coordinated campaign is targeting Hikvision and Dahua surveillance cameras across the Middle East, increasing the risk that compromised devices could support mil...
Iran-linked Hikvision and Dahua surveillance camera targeting campaign
CampaignAbout this happening: A coordinated campaign is targeting Hikvision and Dahua surveillance cameras across the Middle East, increasing the risk that compromised devices could support mil...
Timeline
-
19.08.2026 14:34 3 articles · 13d ago
Hunt.io discloses Operation CameraSwarm against Dahua devices
Initial DisclosureHunt.io says Operation CameraSwarm compromised more than 14,530 Dahua devices between June 17 and July 22, 2026 by combining credential attacks, CVE-2021-33044, CVE-2021-33045, and a P2P relay path; the researchers say 1,923 cameras were configured with a persistent account, 283 were reached through P2P, and confirmed compromises were concentrated in Ukraine and Russia. Users of affected Dahua products are advised to install the corresponding fix software or newer firmware, and ITRES Labs recommends disabling P2P where it is not required and checking firmware against the vendor's download site.
Show sources
- Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P — thehackernews.com — 19.08.2026 14:34
- Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P — thehackernews.com — 19.08.2026 14:34
- Hackers compromise 14,500 Dahua web cameras in 35-day campaign — www.bleepingcomputer.com — 19.08.2026 21:09