threat-intel
Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
High
Summary
Researchers at Hunt.io have uncovered a campaign targeting over 14,500 Dahua IP cameras, leveraging credential attacks and two authentication bypass vulnerabilities (CVE-2021-33044 and CVE-2021-33045) to gain unauthorized access. The campaign, dubbed Operation CameraSwarm, originated from a Russian-speaking operator and involved a P2P relay technique allowing access even behind NAT. Dahua advises customers to install firmware updates and disable P2P where possible.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
