HANGZHOU, China — Over 14,500 internet-connected Dahua devices have been compromised in a massive, coordinated cyberattack campaign. Threat actors exploited a combination of credential brute-forcing, critical authentication bypass vulnerabilities, and the devices’ native Peer-to-Peer (P2P) networking protocols to hijack the hardware.
Dahua, one of the world’s largest manufacturers of video surveillance equipment, has historically struggled with securing its sprawling IoT (Internet of Things) ecosystem. The compromised devices, primarily IP cameras and digital video recorders (DVRs), are being actively recruited into a global botnet architecture.
Exploiting P2P and Auth Bypasses
The sheer scale of the compromise was facilitated by vulnerabilities in how the devices handle external network requests. According to security advisories published Wednesday, attackers bypassed login screens using known authentication flaws, allowing them to inject malicious firmware without ever possessing the administrator password.
Furthermore, the attackers leveraged Dahua’s built-in P2P feature—a protocol designed to make remote device management easier for end-users. By manipulating the P2P handshake, the threat actors effectively tunneled through standard residential and corporate firewalls, establishing direct command-and-control (C2) connections with the compromised hardware.
“IoT devices remain the soft underbelly of network security,” a cybersecurity researcher stated. “When you plug a surveillance camera with a hardcoded password into a corporate network, you are essentially opening a backdoor directly into your infrastructure.”
Corporate Network Risks
While the immediate goal of the attackers appears to be building a botnet for Distributed Denial of Service (DDoS) attacks, compromised edge devices pose a severe threat to enterprise security. Once a camera on a corporate network is hijacked, it can be used as a beachhead to launch lateral attacks against internal databases or proprietary corporate media servers.
To mitigate these risks, IT administrators must aggressively segment IoT devices from the primary corporate network using strict VLAN configurations. Additionally, organizations must disable P2P functionality on all surveillance hardware and ensure firmware is updated to patch known authentication bypass CVEs immediately.
The mass compromise of Dahua devices is a stark reminder that the proliferation of connected hardware requires continuous, vigilant oversight from enterprise security teams.