SHARE
Facebook X Pinterest WhatsApp

ZoomEye Probably Knows Your Dahua Devices’ Passwords

thumbnail
ZoomEye Probably Knows Your Dahua Devices’ Passwords

Many Dahua IoT-based DVR devices can be hijacked by exploiting a five-year-old firmware-based vulnerability, exposing passwords.

Written By
thumbnail
Sue Walsh
Sue Walsh
Aug 7, 2018

Security researchers at NewSky Security have discovered that IoT search engine ZoomEye cached tens of thousands of passwords for Dahua DVR devices. The search engine displays the passwords in clear text, free for the taking, making it easy for even the most unskilled cybercriminal to hack into devices.

Five-Year Vulnerability

This vulnerability isn’t new. In fact, the company has known about it for five years yet taken zero steps to address it. The hacker behind the Brickerbot IoT malware used this weakness, and it appears that ZoomEye has also exploited it. Meanwhile, Dahua continues to sell its woefully insecure devices.

See also: Security report sees clouds for the cloud in 2018

“One does not even need to connect to the Dahua devices to get the credentials. There should be strict regulations for devices to have an update feature, which can be used to automatically push patches to the firmware as soon as the device is connected to the internet,” NewSky Security principle researcher Ankit Anubhav says.

“As long as an IoT device has a strong password and is updated, it should take care of the bulk of the problem. Zero days will still pop up, but most IoT attackers use known passwords/exploits to hack, and they will fail in their attempts.”

Advertisement

Consumers Must Protect Themselves

The Register sent emails to ZoomEye’s administrators asking whether the company planned to address the issue and stop password caching. Emails went ignored. China-located Dahua also ignored inquiries about whether it will push automatic security updates to address the vulnerabilities.

Currently, no one wants to take responsibility for fixing the issues. Right now, it’s up to users. We recommend replacing a Dahua DVR with a more secure model.

thumbnail
Sue Walsh

Sue Walsh is News Writer for RTInsights, and a freelance writer and social media manager living in New York City. Her specialties include tech, security and e-commerce. You can follow her on Twitter at @girlfridaygeek.

Recommended for you...

Top 5 Smart Manufacturing Articles of 2025
Building Resilient and Sustainable Industries With AI, IoT, Software-Defined Systems, and Digital Twins
Peter Weckesser
Nov 26, 2025
Adaptive Edge Intelligence: Real-Time Insights Where Data Is Born
Skype May Be Gone, but P2P Is Here To Stay

Featured Resources from Cloud Data Insights

The Difficult Reality of Implementing Zero Trust Networking
Misbah Rehman
Jan 6, 2026
Cloud Evolution 2026: Strategic Imperatives for Chief Data Officers
Why Network Services Need Automation
The Shared Responsibility Model and Its Impact on Your Security Posture
RT Insights Logo

Analysis and market insights on real-time analytics including Big Data, the IoT, and cognitive computing. Business use cases and technologies are discussed.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.