Hunt.io Research Highlights Remote Access Risks for IP Camera Deployments
A recent threat intelligence report from Hunt.io documented the compromise of more than 14,000 IP cameras over a 35-day period, highlighting risks associated with two commonly used methods of remote video access: port-forwarding and manufacturer-provided peer-to-peer services.
According to the research, the affected devices were concentrated in Ukraine and Russia, although the campaign's scanning activity was global. The researchers said early results appeared in Mexican and Vietnamese networks before the operator narrowed its focus. Hunt.io notified national CERTs and the manufacturer before publishing its findings.
The report identified port-forwarding as one avenue for compromise. Open management ports can be discovered through internet-wide scanning, potentially exposing not only an individual camera but also creating a breach point into a customer's network.
The researchers also identified P2P services as another method used to reach cameras. These manufacturer cloud relays are designed to provide remote access using a serial number or device ID. Cameras accessed through P2P services did not have port-forwarding rules or public IP addresses and remained behind customers' routers.
Once cameras were compromised, the operator installed a backdoor account on nearly 1,900 devices, according to the report. The account is stored separately from the administrator password and can remain in place after a password change or firmware update. The operator also generated account recovery codes offline using serial numbers alone. Those codes remain valid until the manufacturer changes how they are derived, meaning removal of a backdoor account does not invalidate them.
Hunt.io recommended avoiding port-forwarding and disabling P2P services where they are not actively required, including on devices not believed to have been compromised. The report noted that reachability through a serial number is part of how these services are designed to operate rather than a defect addressed through a patch.
Although the report documented Dahua cameras in Ukraine and Russia, the description said the issue is not limited to one brand or region. The compromised population included brands sold under other names, while the underlying exposure can affect IP camera deployments that rely on port-forwarding or manufacturer P2P services.
For professional security companies providing remote video monitoring, the recommendations include identifying cameras, NVRs and DVRs exposed to the internet through port-forwarding or DDNS names and removing those rules. The guidance also calls for disabling manufacturer P2P or cloud services when they are not needed and keeping firmware updated to reduce exposure.
For customers requiring remote video access and monitoring, the description recommends using a secure communication device such as the CHeKT Video Control Panel. According to the company, the panel can make IP cameras cloud-enabled without requiring port-forwarding or P2P services, using encrypted communication and eliminating open ports and password sharing.
CHeKT dealers were also encouraged to review accounts that have not yet been migrated to the platform and begin that process, focusing on sites that may still carry risks associated with traditional remote access methods.
