SDMmag logo
search
Go to Ask SDM AI
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
SDMmag logo
  • NEWS
  • PRODUCTS
  • TOPICS
    • Access Control & Identification
    • Integration & Network Solutions
    • Life Safety & Fire Alarm
    • Monitoring
    • Smart Home
    • Trends & Industry Issues
    • Video Solutions
  • COLUMNS
    • Digital Shuffle
    • Editor's Angle
    • Insider News & Business
    • Integration Spotlight
    • Marketing Madmen
    • Security & the Law
    • Security Comings & Goings
    • Security Networkings
    • Technology @ Work
    • Technology Solutions & Skills
    • SIA Waypoints
    • Cybersecurity Chronicle
  • EXCLUSIVES
    • Annual Industry Forecast
    • Dealer of the Year
    • Project of the Year
    • SDM 100
    • State of the Market Series
    • Systems Integrator of the Year
    • Top Systems Integrator Report
    • TMA Excellence Awards
  • BLOG
  • MEDIA
    • Videos
    • Podcasts
    • Polls
    • White Papers
  • EVENTS
    • Industry Calendar
    • Webinars
  • MORE
    • Classified Ads
    • Newsletters
    • SDM Store
    • State of Security eBook
    • Sponsored Insights
  • BUYERS GUIDE
    • Buyers Guide
    • Take a Tour
  • EMAG
    • eMagazine
    • Archive Issues
    • Monitoring Today
    • Advertise
  • SIGN UP!
Product Manufacturing/DistributionSDM NewswireInsider News & Business

Positive Technologies Identifies Critical Vulnerability in Dahua Cameras

dahua
November 2, 2017

Positive Technologies, a global provider of enterprise security solutions for vulnerability and compliance management, incident and threat analysis, and application protection released an announcement about a critical vulnerability it discovered in firmware of Dahua IP cameras, which are widely used for video surveillance, offering a solution to all who are affected.

“The flaw discovered by Positive Technologies researchers affects hundreds of thousands of cameras all over the world produced by Dahua both under its own brand and as OEM models for other brands,” said Ilya Smith, security researcher at Positive Technologies. 

A vulnerability CVE-2017-3223 gained the highest CVSS base score of 10. This security flaw occurs due to buffer overflow in the Sonia Web interface designed for remote control of the IP camera. An unauthorized user may submit a crafted POST request to the vulnerable Web interface and gain privileged access remotely, which means unlimited control over the IP camera. 

“This vulnerability allows any actions with the camera via software: intercept and modify video traffic, add a device into a botnet to conduct a DDoS attack like Mirai, and much more,” Smith said. “Dahua is the second largest manufacturer of IP cameras and DVRs in the world, but the discovered vulnerability can be easily exploited, which once again demonstrates the actual IoT security level.”

Smith added, “Many of the organizations affected by this likely don’t know that their surveillance cameras are vulnerable to attack,” Smith said, “which is why Positive Technologies made this announcement — to raise awareness of the issue.” 

Users and organizations will first need to check if their devices are vulnerable, then update each vulnerable device’s firmware at www1.dahuasecurity.com/firmware_161.html. Further information about the vulnerability is also available on the CERT website of Carnegie Mellon University [http://www.kb.cert.org/vuls/id/547255].

“This vulnerability allows any actions with the camera via software: intercept and modify video traffic, add a device into a botnet to conduct a DDoS attack like Mirai, and much more,” Smith described. “Dahua is the second largest manufacturer of IP cameras and DVRs in the world, but the discovered vulnerability can be easily exploited, which once again demonstrates the actual IoT security level.”

Looking for quick answers on security topics? Try Ask SDM, our new smart AI search tool. Ask SDM →

According to the research by Positive Technologies, malicious users can get access to over 3.5 million IP cameras all over the world. Moreover, about 90 percent of all DVR systems currently used by small and medium-sized businesses for video surveillance contain certain vulnerabilities and thus can be hacked.

This is not the first partnership between the two companies. In 2013, Positive Technologies helped identify and fix multiple vulnerabilities in Dahua DVR.

As part of a response to this issue, Dahua Technology USA announced a comprehensive set of cyber security initiatives that have been underway for most of 2017. 

“We cannot stress the importance and need for industry professionals to employ cyber security best practices, especially with the previous vulnerability issues Dahua faced back in March,” said Janet Fenner, head of marketing for Dahua North America. “Dahua issued a firmware patch that fixed this specific problem in March 2017 and alerted customers to install new firmware patches.”

Moving forward, Dahua reported in a press release, the company will be implementing new cyber security initiatives incorporated into its products on a global basis including a wide range of activities designed to improve the security of video surveillance products themselves, as well as to improve the security of broader processes, including installation, deployment, and ongoing management. For example, one initiative focuses on authentication for administrative access. As a result, default accounts are no longer included in new devices, with changes implemented in the installation, admin access, and ongoing management processes. Other initiatives resulted in similar broad impacts, including better management of identities, session security, data security, and more.

For current and recent products, many benefits of these initiatives are available in the form of firmware and/or software updates, which will be distributed using software update processes to ensure the enhancements are implemented smoothly. The updated cyber security features were designed and validated in partnership with independent experts including DBAPP Security and Synopsys Technology to ensure the highest security and quality, Dahua reported.

KEYWORDS: cyber security security industry video surveillance news

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
to unlock your recommendations.

Already have an account? Sign In

  • SDM 100

    SDM 100: Top 100 Security Dealers of 2026

    The top 100 security dealers navigated a complex...
    Exclusives
    By: Karyn Hodgson
  • Security camera

    State of the Market: Video Surveillance

    As video surveillance shifts from siloed systems to...
    Video Solutions
    By: Brianna Wilson
  • 2026 Industry Forecast

    SDM 2026 INDUSTRY FORECAST

    Rapid technology advances meet shifting economic...
    Trends & Industry Issues
    By: Karyn Hodgson
Manage My Account
  • SDM Newsletters
  • Online Registration
  • eMagazine Subscriptions
  • Subscription Customer Service
  • Manage My Preferences

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the SDM audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of SDM or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Doctor examining child patient with mother present in medical clinic
    Sponsored byHID

    The Human Side of Hospital Security: How Modern Visitor Management Protects People First

Popular Stories

Video surveillance camera

Why Video Health Monitoring Is a ‘No Brainer’

ESA Board of Directors Q2 26 Elections

Electronic Security Association Announces 2026 Board of Directors Election Results

TMA & SDM Logos

Becklar, Elite & Puget Win 2026 TMA/SDM Monitoring Center Excellence Awards

SDM Dealer of the Year 2026 Promotion

Poll

What’s the most promising trend in the industry?

What’s the most promising trend in the industry?
View Results Poll Archive

Products

Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

See More Products
SDM 100 2026 Rankings

Related Articles

  • hik dahua

    Bill Banning U.S. Gov. From Using Dahua & Hikvision Cameras Signed Into Law

    See More
  • Viakoo

    Viakoo Raises $10 Million in Series A Funding to Scale Automated IoT Vulnerability Remediation

    See More
  • SDM Newswire Default

    ABI Research Identifies Six Transformative Technologies Impacting Industrial Manufacturing

    See More

Related Products

See More Products
  • 9781138378339.jpg

    Surveillance, Crime and Social Control

See More Products
×

Be in the forefront of security intelligence when you receive SDM.

Join over 10,000+ professionals when you subscribe today.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Directories
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing