Hunt.io Finds Dahua Cameras Kept Reconnecting

Hunt.io says Operation CameraSwarm compromised more than 14,530 Dahua IP cameras and NVRs between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and Dahua's serial-number P2P route. The team said 1,923 devices were left with persistent accounts and 283 were reached through P2P. The important part is persistence. The attackers did not need the cameras to be openly exposed on the internet: Dahua's P2P relay can create a route to a device by serial number before normal login checks finish, and the bypass flaws let them get in without standard authentication. That means a password reset alone may not close the door if a planted account or P2P access remains. For teams running Dahua cameras or NVRs, the exposure sits at the device layer and can survive the perimeter they think is doing the blocking. If P2P remote access is enabled, a hidden camera can still be reachable from outside the network, and cleanup has to account for access paths that outlive simple credential changes.

Part of the PlainSec briefing for 2026-08-19

Every edition of this story: Hunt.io Finds Dahua Cameras Kept Reconnecting

CVEs

Sources