HomeSecurityDahua Cameras: Vulnerable to Unauthorized Remote Access

Dahua Cameras: Vulnerable to Unauthorized Remote Access

Unpatched Dahua cameras are susceptible to two authentication bypass vulnerabilities. The authentication bypass flaws are identified as CVE-2021-33044 and CVE-2021-33045, and are both remotely exploitable during the connection process by sending specially crafted data packets to the target device.

Dahua Cameras: Vulnerable to Unauthorized Remote Access

See also: ShellClient Malware: Used in aerospace companies

For more details on how it works, you can check out the proof of concept (PoC) that was part of today's full reveal, which has been posted on GitHub.

This comes a month after Dahua's security advisory urged owners of vulnerable models to upgrade their firmware, but considering how neglected these devices are after their initial installation and setup, it's likely that many of them are still running an old and vulnerable version.

The list of affected models is extensive and covers many Dahua cameras, even some thermal cameras. We searched Shodan and found over 1.2 million Dahua systems worldwide.

Dahua

See also: How a coding bug turns AirTags into malware distributors

It is important to clarify that not all of these devices are vulnerable to the exploit, but the list of affected models is extensive.

Dahua Technology is prohibited from operating and selling products in the United States, as the Chinese company was added to the US Department of Commerce's "Entity List" in October 2019. However, there are still tens of thousands of Dahua cameras actively used in the US, and some of them may not be so obvious.

How to protect your device

In addition to updating your Dahua camera to the latest firmware version available for your model, you should also change the password that came with the device. Leaving root access credentials to “administrator” – “administrator” is a surefire way to expose video feeds sooner or later.

Additionally, enable WPA2 encryption if the camera is wireless and, if possible, create a separate, isolated network for IoT .

Please note that if your model is cloud-enabled, you can automatically get the patch upgrade from the control interface, instead of visiting the Dahua download center.

See also: Android malware has stolen money from 10 million users!

The discovery of the two flaws came on June 13, 2021, so some Dahua cameras remained vulnerable to unauthenticated access for at least 2.5 months, even for devices whose owners applied the firmware update as soon as it was released.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS