Compromised IP Cameras Reveal Security Concerns and Best Practices for CCTVs
- Aug 24
- 2 min read
A CCTV (Closed-Circuit Television) is one of the most popular modern security technologies today. Government institutions, businesses of any size, and modern homes employ CCTVs for monitoring and protection. For public and private safety, simple peace of mind, and real-time monitoring, CCTV has become an invaluable tool. According to Market Reports World, 1.1 billion CCTV cameras were installed worldwide in 2024 across 120 countries, and the number is projected to rise with more complex technologies.
But the rapid implementation of CCTVs is becoming a growing threat to network security and personal privacy.
Hunt.io recently reported on a massive compromise of more than 14,000 IP cameras. These IP cameras were manufactured by Dahua and used worldwide. However, the large number of IP addresses originated from Ukraine, Russia, Mexico, and Vietnam.
According to the report, the attack used four methods of infiltration:
● Brute Force Attacks - more than 12,000 IP cameras were accessed using this method, as it took advantage of cameras with very weak passwords or those that used the default password out of the box.
● Authentication Bypass - hackers exploited a known vulnerability in IP cameras to bypass authentication. Through this attack, more than 1,900 cameras were compromised.
● Backdoor Account - hackers also successfully installed a backdoor on IP Cameras using the p2pwn / p2password persistent account. This type of attack renders the device useless because the account cannot be deleted even with a password change and factory reset.
● Cloud and P2P Relay System - some IP cameras do not have a username and password but use a device User ID to connect with the monitoring device (a mobile phone) via a cloud system. Hackers can exploit the relay system to access and potentially monitor IP cameras. The network and every device connected to it are also compromised.
Additional Vulnerability from Compromised IP Cameras
A compromised IP camera is more than just a camera taken over by hackers. Monitoring IP cameras can be valuable, especially in sensitive situations, but a compromised camera could be the start of a much larger attack. In most homes, IP cameras connect through cloud and P2P relay systems. Unfortunately, these pose a security risk even with stringent password protection.
According to Hacked.Camera ” attackers can use the device (and your Internet connection) however they please. They may be able to attack other computers on your network, and even pinpoint the exact location of your home.” Ignoring the security features of IP cameras for convenience can compromise the entire network and every device connected to it.
Securing Your IP Camera
Home users can disable UID/P2P switches and cloud access through their camera settings. Turning off the Universal Plug and Play feature is also highly recommended because it prevents the camera from automatically opening ports. This process will limit remote access, which ultimately prevents the camera from connecting to the internet.
A separate network is highly recommended to secure a P2P IP Camera. A router can set up a Virtual LAN for the IP cameras to connect without compromising the rest of the devices. A self-hosted server is also a recommended way to use IP cameras without exposing them to potential attacks.

Comments