Dahua Camera Security Under Threat as Operation CameraSwarm Compromises More Than 14,500 Devices
Operation CameraSwarm reportedly compromised over 14,500 Dahua devices using credential attacks, authentication bypass vulnerabilities and P2P relay techniques, highlighting serious Dahua camera security risks and CCTV hacking threats across Ukraine and Russia.
More than 14,500 Dahua devices were reportedly compromised in a cyberattack campaign called Operation CameraSwarm. The campaign targeted Dahua cameras and other devices between June 17 and July 22, 2026, using several methods to gain unauthorised access.
According to cybersecurity researchers at Hunt.io, attackers used stolen or guessed login details, security flaws and a peer-to-peer (P2P) relay technique to access the devices. Most of the affected devices were located in Ukraine and Russia.
The campaign used two serious Dahua security vulnerabilities, identified as CVE-2021-33044 and CVE-2021-33045. Both flaws have a CVSS score of 9.8, making them highly serious security issues. The vulnerabilities allowed attackers to bypass authentication by sending specially prepared data packets to the affected devices. This meant attackers could gain access without going through the normal device identity checks. Hunt.io said that 12,324 devices were compromised through credential attacks. Another 1,923 devices were accessed by exploiting the authentication-bypass vulnerabilities.
A further 283 devices were compromised using a P2P relay method. This technique allowed attackers to reach devices located behind network address translation (NAT), which can normally make direct access more difficult.
The attackers reportedly used a valid device serial number to create a relay path before the usual credential checks were completed. This allowed them to reach some devices without directly connecting to them over the internet. The campaign operator is believed to be Russian-speaking, although researchers have not linked the activity to a specific known threat group.
Dahua has already released firmware updates to fix the two authentication-bypass vulnerabilities. Security researchers recommend that users update affected devices to the latest available firmware as soon as possible. ITRES Labs also recommends disabling P2P functionality if it is not needed. This can reduce the ways attackers may try to reach a device remotely. Users should also change default or weak passwords and regularly check their CCTV and IP camera security settings.
The Operation CameraSwarm attack highlights the risks of leaving internet-connected cameras and other smart devices without the latest security updates. For businesses and users with Dahua devices, keeping firmware updated and removing unnecessary remote-access features can help reduce the risk of CCTV camera hacking and unauthorised access.
This article is based on information from SC World