Fw for Dahua cameras

miljume

n3wb
Feb 11, 2020
14
1
Sweden
I was recently hacked and understand that it was related to a vulnerability mentioned in DHCC-SA-202106-001. I have 2 different models (both purchased from Empiretech): SD49425XB-HNR (V2.800.1341000.0.R.P9.2522.UN.NR, Build Date: 2020-03-12) and IPC-HDW5442TM-ASE (V2.800.0000000.19.R, Build Date: 2020-07-09). From what I understand these FW needs to be patched but I can't find FW files from Empiretech. I don't want to lose the auto tracking on the 49425. Can you help where to go?

BR Mike
 
How are your cameras exposed, e.g, how did you get hacked? P2P? Port forwarding? Infected device on the LAN?
I am going to offer my potentially controversial opinion: whilst I am all for upgrading firmwares to patch vulnerabilities, my approach is basically to always treat IP cams and NVRs as low-security (ironic I know, I mean in terms of network security) devices, which will be hacked if sufficiently exposed.

E.G, I would never be happy exposing an IP camera that I care about via a port forward, even with the latest and greatest firmware. I also am mostly not comfortable using manufacturer P2P solutions, although these can often be a step better than a wide open port forward.

So, I simply isolate the cameras from the internet, VLAN, decent firewall, all the usual stuff you can find here: How to Secure Your Network (Don't Get Hacked!)

Then, I don't even have to worry about whether the firmware is bulletproof or not - I might upgrade for a new feature (if I need it), otherwise I have no need.


I don't know if that makes sense or helps. In a nutshell, perhaps focus on isolating the cameras, instead of patching the cameras themselves?
 
How are your cameras exposed, e.g, how did you get hacked? P2P? Port forwarding? Infected device on the LAN?
I am going to offer my potentially controversial opinion: whilst I am all for upgrading firmwares to patch vulnerabilities, my approach is basically to always treat IP cams and NVRs as low-security (ironic I know, I mean in terms of network security) devices, which will be hacked if sufficiently exposed.

E.G, I would never be happy exposing an IP camera that I care about via a port forward, even with the latest and greatest firmware. I also am mostly not comfortable using manufacturer P2P solutions, although these can often be a step better than a wide open port forward.

So, I simply isolate the cameras from the internet, VLAN, decent firewall, all the usual stuff you can find here: How to Secure Your Network (Don't Get Hacked!)

Then, I don't even have to worry about whether the firmware is bulletproof or not - I might upgrade for a new feature (if I need it), otherwise I have no need.


I don't know if that makes sense or helps. In a nutshell, perhaps focus on isolating the cameras, instead of patching the cameras themselves?

Agree always best.

VPN works fine also

Current Dahua P2P after August 2024 seems to be secure. That said, they can break into anything if they want to.
 
  • Like
Reactions: Mark_M and miljume
On the SD49425XB-HNR you already have the last build that still keeps auto tracking: V2.800.1341000.0.R.P9.2522.UN.NR (2020-03-12). Newer baseline firmwares drop that feature, so flashing anything newer will remove tracking. If tracking matters, leave that one alone and harden around it (VLAN, no P2P/port forwards, VPN for remote) instead of chasing a patched PTZ image.

For the IPC-HDW5442TM-ASE, matching Volt-family builds for the 5442 series usually come via the vendor or the firmware downloads section here, not a public Dahua support page for that exact SKU. Match the hardware gen carefully (pre-S3 vs S3) before flashing, and only upgrade from a known-good package for that exact model string.

DHCC-SA-202106-001 is old enough that isolation is the more reliable fix than hoping a random public bin covers both cameras without side effects.
 
Thank you for your answers!

I have been a bit naive working with port forward but will switchover to P2P instead.

VPN is also an option but would like to make it as easy as possible for the others in my family that want to view the cameras in DMSS

BR
Mike
 
And why would you trust your surveillance cameras on a Chinese based shell company DMSS (Hangzhou Dong Bin Information Technology Co., Ltd.)?? Why not use a US based company like Blue Iris, isolate cameras from internet on your router and use a good VPN. Personally, I would never trust DMSS.
 
I have been a bit naive working with port forward but will switchover to P2P instead.

VPN is also an option but would like to make it as easy as possible for the others in my family that want to view the cameras in DMSS

BR
Mike

I'm not sure how iOS works but on Android connecting to my VPN is as easy as clicking a quick toggle in the notification panel. I have DMSS set to only work on my LAN (so no P2P??). May be worth experimenting with accessing a VPN with your family and if that goes well switch from P2P to VPN.
 
The problems with Dahus P2P were with NVRs and some cameras with FW prior to Aug 2024

Nothing to do with current DMSS app

Check to see if your NVR has P2P enabled and FW version