CVE Tools
Back to feed

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

The Hacker News·By The Hacker News··4 min read
CVE Tools coverage

Researchers at Hunt.io identified a campaign dubbed Operation CameraSwarm that exploited over 14,500 Dahua devices between June and July 2026. The attackers utilized credential stuffing, the authentication bypass vulnerabilities CVE-2021-33044 and CVE-2021-33045, and peer-to-peer relay techniques to gain unauthorized access, with significant impacts reported in Ukraine and Russia. These flaws allow bypass of device identity checks and enable connections to devices behind NAT without initial authentication. Affected users are advised to apply firmware updates from Dahua’s official site, disable unnecessary P2P features, and audit credentials to mitigate these risks.