14,530 Dahua CCTV Cameras and NVRs Compromised in Active Campaign Using Authentication Bypass Flaws
Scope: Dahua IP Cameras, NVRs, and DVRs (All Models Running Unpatched Firmware)
Severity: Red
Hunt.io researchers confirmed that a coordinated campaign compromised 14,530 Dahua network cameras and NVRs between June 17 and July 22, 2026, exploiting a combination of credential attacks, two authentication bypass flaws, and a peer-to-peer relay technique that allowed attackers to access devices behind NAT and firewalls without needing direct network access. Dahua cameras are among the most widely deployed surveillance devices in Uganda across government buildings, bank branches, commercial premises, hotels, and educational institutions, making this a direct and immediate concern for the local security landscape. Compromised cameras can be used for unauthorized surveillance, recruitment into DDoS botnets, and as a persistent entry point into the networks they are connected to. Organizations must update all Dahua camera and NVR firmware to the latest available version from the official Dahua Support portal, replace all default and shared credentials with strong unique passwords, and ensure camera management interfaces are not accessible from the internet.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.