pfsense firewall protect your Dahua devices

Reported by international hackers news :   

https://thehackernews.com/2026/08/hackers-compromised-14500-dahua-devices.html
https://www.it-daily.net/shortnews-en/critical-security-vulnerabilities-in-dahua-surveillance-cameras
https://cybernews.com/security/security-flaws-in-dahua-cameras-being-exploited/

Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique.

The activity, codenamed Operation CameraSwarm, was reconstructed from a 407 MB exposed working directory containing 2,616 files across 234 subdirectories, including tooling, logs, shell history, and campaign records, with the researchers saying confirmed compromises were concentrated in Ukraine and Russia.

The researchers said 1,923 cameras were configured with a persistent account during the operation and 283 were reached through the P2P path.

Users of affected Dahua products are advised to install the corresponding fix software or newer firmware, while ITRES Labs recommends disabling P2P where it is not required and checking firmware against the vendor's download site.

Hunt.io attributed the 14,530-plus total to three attack paths -

  • Credential attacks: 12,324 unique IP addresses across 13,229 campaign records.
  • Authentication bypass: 1,923 cameras reached using CVE-2021-33044 and CVE-2021-33045, which Hunt.io said were also configured with the persistent account.
  • P2P relay: 283 cameras identified by serial number, including devices located behind network address translation (NAT).

The two 2021 flaws are authentication-bypass vulnerabilities in Dahua cameras and related products. Dahua's advisory rates them 8.1 on the CVSS scoring system and lists fixed firmware, while the U.S. National Vulnerability Database (NVD) currently assigns each a CVSS score of 9.8.

"Attackers can bypass device identity authentication by constructing malicious data packets," Dahua said in its advisory.

A NetKeyboard client type triggers CVE-2021-33044 during authentication, while CVE-2021-33045 involves a loopback login request using the 127.0.0.1 address, according to the original disclosure from security researcher Bashis.

As of August 19, 2026, both flaws remain listed in the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog, which records them as Dahua IP camera authentication-bypass vulnerabilities and advises applying vendor mitigations or discontinuing use if mitigations are unavailable.

As of August 19, 2026, the public p2pwn repository remains accessible and independently confirms that the tool accepts Dahua serial numbers as input, checks CVE-2021-33044 and CVE-2021-33045, and contains a default dummy-account configuration.

Two CVE labels associated with the recovered tooling do not describe the P2P behavior: CVE-2024-39943 is assigned by NVD to an operating-system command-injection flaw in Rejetto HFS, while Dahua describes CVE-2025-31702 as a privilege-escalation flaw that requires previously obtained normal-user credentials.

ITRES Labs described the serial-number relay exposure as a non-CVE issue and said its testing found that the P2P path was reinforced in firmware released after mid-2024.

The firm advised defenders to disable P2P unless required, restrict Easy4IP connectivity where appropriate, update devices using firmware from the vendor's website, use strong unique credentials, remove unused accounts, and segment video surveillance systems.

Dahua's advisory directs customers to install the listed repair software or newer firmware. The Hacker News has reached out to Dahua to confirm the campaign scope and P2P findings and will update this story with any response.

The researchers described the operator as Russian-speaking based on language artifacts recovered from the working directory, but the activity has not been attributed to a named threat actor, a Russian government entity, or another known group. The firm assessed with moderate confidence that parts of the toolkit may have been designed to transfer camera access to a third party.

As of August 19, 2026, the campaign-specific totals of more than 14,530 devices, 1,923 persistent accounts, 283 P2P compromises, and the 89.4% open-channel figure remain attributed to Hunt.io. The public primary sources reviewed for this story corroborate the two old authentication bypasses, the p2pwn tool configuration, and the underlying serial-number P2P mechanism, but do not independently confirm those CameraSwarm counts.

 

We are offering Netgate firewall with auto-sense/auto-defense of CVE-2024-39943; CVE-2025-31702; CVE-2021-33044; CVE-2021-33045; CVE-2025-31702 which enhance protection of your Dahua devices.  call us for detail solutions ...