Critical Dahua Camera Backdoor Persists After Factory Reset CVE-2023-XXXX
Key Takeaways More than 14,000 internet-connected Dahua cameras were compromised in a 35-day campaign. Attackers exploited known authentication bypass vulnerabilities (CVE-2021-33044, CVE-2021-33045)...
Key Takeaways
- More than 14,000 internet-connected Dahua cameras were compromised in a 35-day campaign.
- Attackers exploited known authentication bypass vulnerabilities (CVE-2021-33044, CVE-2021-33045) and weak credentials.
- A critical backdoor allows persistent administrative access that survives password changes and, in most cases, factory resets.
- The campaign leveraged Dahua’s cloud relay service to target cameras even behind NAT.
- Patches are available for the initial access flaws, but many devices remain unpatched.
Thousands of Dahua Cameras Compromised with Persistent Backdoor
A widespread cyberattack has infiltrated over 14,000 internet-connected Dahua surveillance cameras, revealing a concerning vulnerability in security infrastructure. This extensive 35-day operation highlights how easily compromised surveillance equipment can provide long-term, stealthy access to video feeds and device configurations for malicious actors.
Table Of Content
The global campaign saw significant concentrations of compromised devices in Ukraine and Russia. It underscores a persistent challenge in cybersecurity: unattended internet-of-things (IoT) devices can become entrenched footholds for adversaries, providing durable and hidden access points.
Attack Methodology and Discovery
The attackers initiated their campaign by scanning for exposed camera management interfaces. They then attempted to exploit devices using common weak credentials and two previously identified authentication-bypass vulnerabilities, CVE-2021-33044 and CVE-2021-33045, targeting unpatched systems.
A particularly insidious aspect of the attack involved exploiting a cloud relay mechanism. This allowed attackers to reach cameras even when they were situated behind Network Address Translation (NAT) by using their serial numbers. This bypasses a common network security measure, making even non-public devices susceptible to targeting.
The activity was brought to light by analysts at Hunt.io, who discovered an openly accessible operator directory containing 2,616 files and the campaign’s operational tooling. Hunt.io said in a report that their analysis of the recovered materials revealed multiple attack vectors, mechanisms for persistent access, and an unrelated Windows-specific payload.
Beyond simply viewing live feeds, the attackers’ toolkit was designed for comprehensive control. It facilitated the collection of credentials, captured camera snapshots, and enabled the export of device records in a format optimized for large-scale administrative tasks. Furthermore, researchers uncovered methods for generating offline recovery codes, which could grant administrative reset capabilities even after a legitimate owner changed their device password.
Dahua Camera Backdoor Survives Resets and Password Changes
The most alarming discovery is the sophisticated persistence mechanism. After successfully gaining administrator privileges, typically through the exploitation of CVE-2021-33044 or CVE-2021-33045, the attackers installed a separate, unauthorized account via the camera’s remote management interface. This rogue account operates independently of the primary administrator password, meaning that a password change by the legitimate owner does not remove the backdoor. In fact, for the majority of affected firmware versions, even a factory reset fails to eradicate this hidden access. Hunt.io identified this persistent account on 1,923 cameras.
This level of persistence elevates the response to a suspected compromise from a simple password reset to a full-scale forensic investigation, particularly critical for organizations deploying these cameras in sensitive locations.
While patches for the initial authentication bypass flaws are available, a significant number of Dahua cameras remain unpatched and exposed, making them attractive targets. The exploitation methods leverage vulnerabilities that allow attackers to impersonate trusted hardware controllers or make requests appear to originate from the camera itself, both leading to unauthorized administrator access.
Researchers noted that a label within the recovered toolkit for the persistent account technique references an unrelated vulnerability. Therefore, defenders should prioritize the observed behavior and indicators of compromise rather than relying on this potentially misleading identifier.
Recovery Codes Expand Risk
The campaign further exploited a cloud relay feature, allowing attackers to locate and communicate with cameras using their serial numbers. Logs indicate that 89.4% of tested live serial numbers returned a channel that did not require authentication. This effectively bypasses the security typically provided by placing a camera behind a router, exposing devices that might otherwise be considered protected. Attackers then used this access to generate offline recovery codes for live devices. These codes enable password recovery without needing the existing device credentials, making the threat even more enduring as removing the unauthorized account may not permanently revoke access.
The broad implications of unpatched surveillance equipment are not new. Similar abuses of unpatched cameras have been observed in operations targeting US networks, emphasizing that camera security is a critical operational concern, not merely a minor maintenance detail.
What You Should Do
- Audit All Accounts: Conduct a thorough audit of all accounts on every Dahua camera.
- Remove Unauthorized Accounts: Immediately remove any unauthorized or suspicious accounts found.
- Rotate Credentials: Change passwords for all camera accounts and any linked recording devices.
- Investigate Access: Determine if footage, device settings, or passwords were accessed or exfiltrated.
- Disable P2P: If not essential, disable Peer-to-Peer (P2P) features on your cameras.
- Restrict Management Access: Limit camera management services to trusted internal networks only.
- Apply Firmware Updates: Promptly apply all available firmware updates from Dahua to patch CVE-2021-33044 and CVE-2021-33045, and to prevent the generation of new recovery codes while invalidating old ones.
- Monitor Network Activity: Network teams should implement alerts for suspicious controller or loopback login patterns.
- Review Security Tool Exclusions: Windows teams should investigate any broad security tool exclusions that might hide malicious activity.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.