Operation CameraSwarm exploitation of Dahua authentication-bypass flaws
Case score 78
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 78
- Main story score
- 78
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 2
- Vulnerability Primary anchor for the exploited Dahua authentication-bypass flaws. main
- Campaign Direct exploitation evidence and operational fallout for the same CVEs. context
- Advisory Mitigation Current KEV tracking and required mitigation guidance for the same CVEs. context
Overview
Latest development Open development history Operation CameraSwarm uses Dahua camera authentication bypasses Hunt.io said Operation CameraSwarm compromised more than 14,530 Dahua devices between June 17 and July 22, 2026 by combining credential attacks, CVE-2021-33044, CVE-2021-33045, and a P2P relay path. The researchers said 1,923 cameras were configured with a persistent account and 283 were reached through P2P, while Dahua and CISA still track the two authentication-bypass flaws and advise installing vendor fixes or newer firmware.
-
Hunt.io discloses Operation CameraSwarm against Dahua devices
Hunt.io says Operation CameraSwarm compromised more than 14,530 Dahua devices between June 17 and July 22, 2026 by combining credential attacks, CVE-2021-33044, CVE-2021-33045, and a P2P relay path; the researchers say 1,923 cameras were configured with a persistent account, 283 were reached through P2P, and confirmed compromises were concentrated in Ukraine and Russia. Users of affected Dahua products are advised to install the corresponding fix software or newer firmware, and ITRES Labs recommends disabling P2P where it is not required and checking firmware against the vendor's download site.