Hacked DAHUA cam and added that names

yeah the major vulnerabilities that allows this is to happen is CVE-2025-31702 and CVE-2021-33044/CVE-2021-33045 , seen how its done so i know, TIGOS idea of creating accounts using those trolls accounts is good if you want to still use p2p, might be wort a shot.
I've also seen many videos of how this vulnerability is exploited.
Found a way to check if my camera is vulnerable to these vulnerabilities.
( GitHub - umair-aziz025/dahua-cve-research: Dahua IP camera CVE research toolkit (CVE-2021-33044/33045, CVE-2025-31700/31701) )

But that's all just theory.

Haven't seen a freely available app for hacking this kind of device yet.
Actually, to my delight.
Because immediately there will be a ton of hacks everywhere.
 
Haven't seen a freely available app for hacking this kind of device yet.
Actually, to my delight.
Because immediately there will be a ton of hacks everywhere.
unfortunately tools have been made and being sold on telegram channels, one of which was forked using this on github, i saw a demo posted by a seller who showed it could hack quite a few so yeah the threat is real and could affect a majority of cams that have not been updated after 2024
 
  • Like
Reactions: TIGOS1
I found this thread when searching for "dahua", "oldworld", "newworld" on Google and it seems one of my devices has been "hacked".

But I still don't know how and when, but the first thing to mention is:
No new user ACCOUNTS have been created, only two user GROUPS named "oldworld" and "newworld".
The admin accounts password has not been changed, no other accounts exists. It contained Uppercase, lowercase, special characters, 8 chars long.

On this network I use the same router from the beginning (FritzBox 7590) which has always been up to date.
I never used UPnP or a single Port Forwarding on the router. I deactived all those features on my cams.
I only used P2P for some hours on my VTO2000A to test the app to see who is at my door and decided I don't need this.

Cam Model is a IPC-HDBW1320E-W
System Version 2.400.0000000.16.R, Build Date: 2017-08-31
WEB Version 3.2.1.490211
ONVIF Version 16.12(V2.3.1.458331)

Rather old, firmware was already installed when shipping and no newer version was found at any time.

My questions here are:
How the heck could someone manipulate the camera when it was not reachable from the outside at any tme?
Was P2P/Easy4ip enabled by default when shipping and they broke in while I configured the cam and turned it off?
Why did they create two user groups but no account?

I checked a camera of the same type on my network, but no additional users or groups where there.
No strings where added to the Label setting or somewhere else.

The cameras monitor uncritical outdoor areas.
Any ideas what I should check for?

The only (somewhat) suspicious entry in the log is:
10252024-10-15 20:57:00SystemLock Account

All other log entries are from 2026, two weekly auto-reboots:
7042026-06-20 04:37:47SystemSave Configuration
7052026-06-20 04:37:47SystemEvent Begin
7062026-06-20 04:37:47SystemEvent Begin
7072026-06-20 04:37:46SystemStart up
7082026-06-20 04:37:46SystemAuto Maintain
7092026-06-20 04:37:00SystemReboot

And a lot of "Event begin", "Event ends" which motion detection I guess.

Any suggestions?
 
Last edited:
I found this thread when searching for "dahua", "oldworld", "newworld" on Google and it seems one of my devices has been "hacked".

But I still don't know how and when, but the first thing to mention is:
No new user ACCOUNTS have been created, only two user GROUPS named "oldworld" and "newworld".
The admin accounts password has not been changed, no other accounts exists. It contained Uppercase, lowercase, special characters, 8 chars long.

On this network I use the same router from the beginning (FritzBox 7590) which has always been up to date.
I never used UPnP or a single Port Forwarding on the router. I deactived all those features on my cams.
I only used P2P for some hours on my VTO2000A to test the app to see who is at my door and decided I don't need this.

Cam Model is a IPC-HDBW1320E-W
System Version 2.400.0000000.16.R, Build Date: 2017-08-31
WEB Version 3.2.1.490211
ONVIF Version 16.12(V2.3.1.458331)

Rather old, firmware was already installed when shipping and no newer version was found at any time.

My questions here are:
How the heck could someone manipulate the camera when it was not reachable from the outside at any tme?
Was P2P/Easy4ip enabled by default when shipping and they broke in while I configured the cam and turned it off?
Why did they create two user groups but no account?

I checked a camera of the same type on my network, but no additional users or groups where there.
No strings where added to the Label setting or somewhere else.

The cameras monitor uncritical outdoor areas.
Any ideas what I should check for?

The only (somewhat) suspicious entry in the log is:
10252024-10-15 20:57:00SystemLock Account

All other log entries are from 2026, two weekly auto-reboots:
7042026-06-20 04:37:47SystemSave Configuration
7052026-06-20 04:37:47SystemEvent Begin
7062026-06-20 04:37:47SystemEvent Begin
7072026-06-20 04:37:46SystemStart up
7082026-06-20 04:37:46SystemAuto Maintain
7092026-06-20 04:37:00SystemReboot

And a lot of "Event begin", "Event ends" which motion detection I guess.

Any suggestions?
All firmware with year before 2024-04 is hackable

That devices may be hacked by p2p protocol
 
Hackers compromise 14,500 Dahua web cameras in 35-day campaign

In a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and Russia.

The operation ran for at least 35 days between June 17 and July 22, compromising devices by exploiting vulnerabilities, brute-forcing logins, and using offline recovery codes from serial numbers for cloud-registered cameras.
 
All firmware with year before 2024-04 is hackable

That devices may be hacked by p2p protocol
It would appear I too got hacked. My setup is a Dahua NVR and 6 Dahua IPCams attached. Four out of the 6 camera had their Title/Label settings changed to "PROPERTY OF FCAM" plus a discord address and "Cat & SkyFlizz". I was able to change the Title section back to what I had before but the characters in the bottom right quadrant of the camera-view is proving more challenging.
 

Attachments

  • Screenshot 2026-08-23 at 17.52.22.png
    Screenshot 2026-08-23 at 17.52.22.png
    3.7 MB · Views: 18
It would appear I too got hacked. My setup is a Dahua NVR and 6 Dahua IPCams attached. Four out of the 6 camera had their Title/Label settings changed to "PROPERTY OF FCAM" plus a discord address and "Cat & SkyFlizz". I was able to change the Title section back to what I had before but the characters in the bottom right quadrant of the camera-view is proving more challenging.
Only "factory default" to correct that
 
I may do that for peace of mind once I secure my NVR and IP cams from future attacks. But I was able to get rid of the “digital graffiti” in the lower right quadrant by going into the cameras’ settings.

But some little guy in eastern sloblovia still owns your NVR/Computer