Over 14,000 Dahua security cameras connected to the internet have been hacked in a 35-day online attack that affected devices around the world. This shows the rising danger of unsafe and unprotected surveillance systems.
Researchers at Hunt.io found the operation by looking into a public directory with 2,616 files related to the attackers. The campaign aimed at unprotected camera management services, used weak passwords, and took advantage of two security flaws—CVE-2021-33044 and CVE-2021-33045—to get admin access.
The attack was very risky because it allowed ongoing hidden access. Attackers made another admin account that worked separately from the main password. Hunt.io found 1,923 hacked cameras using the wrong account, and factory resets usually did not get rid of the access on most of the affected systems.
The attackers misused a cloud relay system to access cameras behind NAT with device serial numbers. Researchers discovered that 89.4% of live serial numbers tested gave an open channel, possibly letting attackers reach devices not directly online.
Attackers not only accessed video feeds without permission but also gathered login details, took pictures from cameras, and got device information. They even created recovery codes offline, which means they could still get admin access after changing passwords.
Security teams should check camera accounts, take off users who shouldn’t have access, change camera and recorder passwords, look over access logs, turn off extra P2P features, limit management access to safe networks, and install the newest Dahua firmware updates.
The campaign illustrates that internet-connected cameras have evolved beyond mere physical-security devices; they can now serve as enduring entry points for attackers and potential gateways into larger organizational networks.
TP-Link Archer AX55 V4 Flaws Could Enable RCE and Credential Theft
TP-Link has found two security flaws in its Archer AX55 V4 router. These issues might let attackers on the local network crash services, take administrator passwords, and possibly run harmful code on affected devices.
The flaws, listed as CVE-2026-18167 and CVE-2026-18330, impact the router’s EasyMesh and web login parts. TP-Link has launched firmware 1.2.1 Build 20260527 to fix these issues.
CVE-2026-18167 is a serious flaw. It is a high-risk buffer overflow in the EasyMesh part, with a score of 7.7. When Mesh mode is on, a local attacker can send special input to the easymesh daemon. This could cause a crash or allow them to run code from afar.
The second flaw, CVE-2026-18330, has a CVSS v4 score of 6.1. It comes from a fixed RSA-1024 private key in the web login section. A hacker on the same network who grabs an HTTP-based administrator login could possibly decrypt the admin password and take over the router settings.
Successful attacks could let hackers change DNS settings, watch network traffic, send users to different places, check connected devices, or use the router to launch more attacks.
TP-Link asks Archer AX55 V4 users to update their firmware right away. They should turn off Mesh mode if not needed. They should avoid using HTTP for management, create strong and unique admin passwords, and limit access to the router to trusted networks.
InfoSecBulletin Cybersecurity for mankind
