Tendvane

← All articles

NetworkAugust 20, 2026

14,500 security cameras taken over using flaws patched five years ago

Someone left a web server open. Inside it, the threat intelligence firm Hunt.io found 407 MB of a working directory - tools, logs, shell history, campaign records - belonging to whoever had spent the previous five weeks collecting security cameras.

The tally, published on 18 August: 14,530 Dahua IP cameras compromised between 17 June and 22 July. Three methods ran side by side. Most of it was plain brute force, scanning TCP port 37777 - Dahua's management protocol - and guessing credentials across 12,324 addresses. On 1,923 cameras the operator used CVE-2021-33044 and CVE-2021-33045, authentication bypasses Dahua patched back in 2021, to plant a backdoor account called p2pwn. That account survives a password change, and on most firmware it survives a factory reset, because it's stored separately from the admin credentials. A further 283 cameras sat safely behind home routers and were reached anyway, through Dahua's own cloud relay, using little more than serial numbers. Confirmed victims cluster in Ukraine and Russia, though the scanning was worldwide, and the take was camera snapshots and device lists pushed out over Telegram.

The five-year-old CVE numbers are the part worth sitting with. A camera is a small computer running an operating system, and hardly anyone ever updates one - it goes on the wall, it works, and it's ignored for a decade. Patches for these two have existed since 2021.

If you own a Dahua camera, or one of the many rebadged models built on its firmware, update the firmware, look through the user list for an account named p2pwn, and switch off P2P if you never use the phone app. Changing the password on its own won't clear it. Tendvane's network scan lists every device currently on your Wi-Fi, which tends to be the moment people remember the camera in the hallway.

Sources

Download Tendvane