Ethical Hacking News
Hackers Compromised Over 14,500 Dahua Devices via Credential Attacks and Authentication Bypasses
A recent security breach has left thousands of Dahua devices vulnerable to exploitation by hackers. More than 14,530 Dahua devices were compromised between June 17 and July 22, 2026, using credential attacks, authentication bypasses, and a peer-to-peer (P2P) relay technique. The breach was attributed to a Russian-speaking operator, but the activity has not been attributed to a named threat actor, a Russian government entity, or another known group. Dahua has advised customers to install the corresponding fix software or newer firmware, while ITRES Labs recommends disabling P2P where it is not required and checking firmware against the vendor's download site. The breach highlights the importance of prioritizing security and keeping software up to date.
Over 14,530 Dahua devices were compromised in a recent security breach. The breach was attributed to three attack paths: credential attacks, authentication bypasses, and P2P relay. Credential attacks involved 12,324 unique IP addresses, while authentication bypasses were facilitated by two vulnerabilities in Dahua cameras. P2P relay involved 283 cameras identified by serial number, including devices behind network address translation (NAT). Dahua has advised customers to install fix software or newer firmware to prevent exploitation. The breach highlights the importance of keeping software up to date and implementing robust security measures.
A recent security breach has left thousands of Dahua devices vulnerable to exploitation by hackers. According to a report by Hunt.io, a cybersecurity research firm, more than 14,530 Dahua devices were compromised between June 17 and July 22, 2026, using credential attacks, authentication bypasses, and a peer-to-peer (P2P) relay technique.
The compromised devices were configured with persistent accounts, which allowed hackers to bypass device identity authentication and gain unauthorized access to the devices. The researchers attributed the breach to three attack paths: credential attacks, authentication bypasses, and P2P relay.
The credential attacks involved 12,324 unique IP addresses across 13,229 campaign records, while the authentication bypasses were facilitated by two vulnerabilities in Dahua cameras and related products, CVE-2021-33044 and CVE-2021-33045. These vulnerabilities allowed hackers to bypass device identity authentication by constructing malicious data packets.
The P2P relay technique involved 283 cameras identified by serial number, including devices located behind network address translation (NAT). The researchers noted that the P2P path was separate from the two authentication-bypass flaws and that the serial-number relay exposure was a non-CVE issue.
The breach was attributed to a Russian-speaking operator, but the activity has not been attributed to a named threat actor, a Russian government entity, or another known group. The researchers assessed with moderate confidence that parts of the toolkit may have been designed to transfer camera access to a third party.
In light of this breach, Dahua has advised customers to install the corresponding fix software or newer firmware, while ITRES Labs recommends disabling P2P where it is not required and checking firmware against the vendor's download site.
The breach highlights the importance of keeping software up to date and implementing robust security measures to prevent exploitation by hackers. It also underscores the need for device manufacturers to prioritize security and to implement adequate measures to prevent such breaches.
The researchers described the operator's recovered code as recording 89.4% of live serial numbers returning an open channel without authentication. However, this figure remains a campaign-specific claim from the recovered operator material and has not been independently reproduced by ITRES Labs, Dahua, or a public computer emergency response team advisory.
In conclusion, the recent breach of over 14,500 Dahua devices highlights the importance of prioritizing security and keeping software up to date. It also underscores the need for device manufacturers to implement adequate measures to prevent exploitation by hackers.
Related Information:
https://www.ethicalhackingnews.com/articles/Hackers-Compromised-Over-14500-Dahua-Devices-via-Credential-Attacks-and-Authentication-Bypasses-ehn.shtml
https://thehackernews.com/2026/08/hackers-compromised-14500-dahua-devices.html
https://nvd.nist.gov/vuln/detail/CVE-2021-33044
https://www.cvedetails.com/cve/CVE-2021-33044/
https://nvd.nist.gov/vuln/detail/CVE-2021-33045
https://www.cvedetails.com/cve/CVE-2021-33045/
Published: Wed Aug 19 09:53:07 2026 by llama3.2 3B Q4_K_M