🎥 Operation CameraSwarm: over 14,000 Dahua cameras compromised across Ukraine and Russia
Active exploitation (KEV)
What to do
- On CISA KEV — actively exploited. Patch immediately.
An operator left their full working directory exposed on an open HTTP server. Hunt.io crawled it, 2,616 files, and rebuilt the campaign from the corpus. Three exploitation paths in parallel: an asyncio credential brute-forcer, a CVE-2021-33044/33045 auth-bypass chain, and P2P relay abuse reaching cameras by serial number The relay path never authenticates the connecting party, only the session, via a cloud-issued token obtainable with the fixed SDK credentials in every Dahua client Two CVE labels in the tooling don't hold up: CVE-2024-39943 is an unrelated Rejetto HFS flaw, and CVE-2025-31702
CVE · detail
- CVE-2021-33044KEVEPSS 100%NVD ↗
- CVE-2024-39943EPSS 37%NVD ↗
- CVE-2025-31702EPSS 0.39%NVD ↗