Hunt.io uncovers large-scale exploitation of Dahua devices using legacy vulnerabilities and peer-to-peer relay tactics

A recent campaign dubbed Operation CameraSwarm has compromised over 14,500 Dahua surveillance devices across Ukraine and Russia, exploiting outdated flaws and peer-to-peer relay methods, raising urgent security concerns for industry and government alike.

Hunt.io says a recent campaign compromised more than 14,530 Dahua devices over a five-week period between 17 June and 22 July 2026, combining password attacks, two older authentication-bypass flaws and a peer-to-peer relay method. The firm said the activity, which it calls Operation CameraSwarm, was reconstructed from an exposed 407 MB working directory containing campaign logs, tooling, shell history and other records. It said the confirmed incidents were heavily concentrated in Ukraine and Russia.

According to Hunt.io, the operation used three distinct access paths. Most of the activity involved credential attacks against 12,324 unique IP addresses across 13,229 records. A further 1,923 cameras were reached through CVE-2021-33044 and CVE-2021-33045, both Dahua authentication-bypass vulnerabilities, and those devices were also said to have been set up with a persistent account. Another 283 devices were identified through a P2P relay route, including systems behind network address translation.

The two 2021 flaws remain significant because they are widely documented and still appear in CISA’s Known Exploited Vulnerabilities catalogue. Dahua says the bugs can be used to bypass device identity checks with malicious packets, and the US National Vulnerability Database currently rates each one at 9.8 out of 10. Security researcher Bashis originally described one issue as a NetKeyboard authentication path and the other as a loopback login request using 127.0.0.1. CISA has warned agencies to apply vendor mitigations or stop using the product if fixes are unavailable.

The P2P component is more nuanced. ITRES Labs previously reported that, on older firmware, a valid Dahua serial number could be enough to establish an Easy4IP relay path before the camera completed its own login checks, making a device reachable through the vendor’s relay infrastructure. A public proof-of-concept repository also shows how Dahua P2P uses a serial number to locate a device and open a tunnel to a camera or recorder. Hunt.io said its recovered material indicated that 89.4% of live serial numbers returned an open channel without authentication, but that figure has not been independently verified. ITRES Labs says the relay behaviour was tightened in firmware released after mid-2024 and recommends disabling P2P where it is not needed, restricting Easy4IP access, using unique credentials and keeping devices updated.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.