Cybersecurity researchers at Hunt.io have uncovered a massive IoT exploitation campaign dubbed Operation CameraSwarm. In this attack, operation cameraswarm dahua cameras were successfully compromised, hijacking more than 14,530 surveillance devices in just over a month. By stringing together credential attacks, legacy authentication bypass vulnerabilities, and peer-to-peer (P2P) relay abuse, threat actors built a vast, silent network of hijacked cameras.
The campaign’s inner workings were discovered when researchers identified an exposed 407 MB working directory belonging to the attackers. This server contained over 2,600 files, including exploitation tooling like the p2pwn repository, logs, and detailed campaign records, providing an unprecedented look into modern IoT botnet operations.
If your organization relies on Dahua surveillance equipment, it is critical to understand how operation cameraswarm dahua cameras were breached, as traditional network perimeter defenses (like NAT) were completely bypassed during this campaign.
The Three Pillars of Operation CameraSwarm
The threat actors did not rely on a single zero-day vulnerability. Instead, they utilized a “shotgun approach,” combining three distinct attack paths to maximize their infection rate across the internet.
First, the attackers launched massive credential stuffing and brute-force attacks, targeting devices with default or weak passwords. This brute-force infrastructure spanned over 12,000 unique IP addresses, systematically probing internet-exposed cameras.
Second, they actively exploited two older, critical authentication-bypass vulnerabilities: CVE-2021-33044 and CVE-2021-33045. These flaws, which carry a maximum CVSS score of 9.8 on the National Vulnerability Database (NVD), allow attackers to bypass identity authentication by sending specifically crafted malicious data packets. As detailed in the original Full Disclosure by Bashis, nearly 2,000 cameras were breached using this method, with the attackers leaving behind a persistent backdoor account.
Third, and most concerningly, the attackers abused the Dahua P2P (Peer-to-Peer) Relay protocol (often associated with Easy4IP). Tools like the dh-p2p repository demonstrate how attackers input valid Dahua serial numbers to establish an open tunnel to cameras hidden safely behind Network Address Translation (NAT) firewalls. ITRES Labs noted that older firmware allowed this relay path to be established without prior authentication, leaving login checks entirely to the device’s web application.

| Vulnerability / Vector | Details & Impact |
|---|---|
| CVE-2021-33044 | Authentication bypass via NetKeyboard spoofing (CVSS 9.8) |
| CVE-2021-33045 | Loopback login request bypass via 127.0.0.1 (CVSS 9.8) |
| CVE-2024-39943 | OS command-injection flaw in Rejetto HFS (Tooling Label) |
| P2P Relay Abuse | Bypasses NAT firewalls via serial number tunnels (Easy4IP) |
How to Secure Your Dahua Devices
Because CVE-2021-33044 and CVE-2021-33045 remain on the CISA Known Exploited Vulnerabilities (KEV) catalog, securing these devices is a matter of federal compliance for many organizations.
The most immediate step is to review the official Dahua Security Advisory and update the device firmware. Dahua has also addressed related privilege-escalation flaws like CVE-2025-31702 in newer releases, which reinforces the P2P connection protocols.
Furthermore, IT security teams should strictly disable P2P and Easy4IP connectivity unless it is absolutely necessary for remote viewing. Network administrators should place all video surveillance systems on isolated VLANs, ensuring that even if a camera is compromised, the attacker cannot pivot laterally into the corporate IT network.
Related Resource: IoT devices are a prime target for botnets. Learn how to protect your network against large-scale DDoS attacks in our guide on Agentic AI Cybersecurity Threats in 2026.
FAQ: operation cameraswarm dahua cameras
What is Operation CameraSwarm?
Operation CameraSwarm is a massive IoT exploitation campaign discovered by Hunt.io that compromised over 14,500 Dahua surveillance devices using a combination of credential attacks, legacy CVE exploits, and P2P relay abuse.
How did attackers bypass NAT firewalls?
The attackers abused Dahua’s built-in P2P (Peer-to-Peer) relay infrastructure. By knowing a device’s serial number, they could establish a tunnel through the vendor’s cloud servers to reach the camera, even if it was hidden behind a secure corporate NAT firewall.
Are CVE-2021-33044 and CVE-2021-33045 still a threat?
Yes. Despite being patched years ago, thousands of unpatched Dahua cameras remain internet-facing. Both vulnerabilities are actively exploited in the wild and remain on the CISA KEV catalog due to their critical CVSS 9.8 ratings.
Reported by CyberUpdates365 Desk
Delivering the latest insights on enterprise security, federal AI directives, and the future of IT infrastructure. Follow us for daily updates on how technology is reshaping the corporate landscape.




