CCTV cybersecurity and legacy coax estates
What an analogue estate takes off the table, what it puts on, and why a hybrid recorder breaks the segmentation plan drawn around it.
The coax did not go away when IP arrived. Vendors put high-definition signalling on it instead, and that silicon is still in production: Techpoint's current catalogue lists receiver parts badged HD-TVI 4.0 and HD-TVI 5.0, Nextchip still markets AHD™ with a second generation listed as coming, and Dahua still sells HDCVI as four product families. An estate built on any of them has no camera-side attack surface in the sense the rest of this site uses the term. It also has a problem an IP fleet does not have: nothing on that cable can prove it is a camera.
What is on the coax#
| Scheme | Originator | What the vendor publishes | Up-the-coax control | IP-addressable? |
|---|---|---|---|---|
| AHD | Nextchip | AHD™, "Delivering Exceptional Value by Analog HD Transmission"; 1st-generation parts NVP6321 and NVP6324 at "Upto 1080p@30fps" | Not described on Nextchip's AHD page | No |
| HD-TVI | Techpoint | Receiver lines badged HD-TVI 4.0 and 5.0; parts listed as "1080P/720P/D1 receiver" and as a "3-8 MP Receiver Supporting Coaxial Audio" | Yes | No |
| HD-CVI | Dahua | HDCVI cameras, HDCVI PTZ cameras, HDCVI recorders and HDCVI accessories, sold as current lines1 | Yes | No |
Trade documentation from 2018 describes HD-CVI and HD-TVI as carrying bidirectional control — "video/audio and camera control over one coaxial line" — at distances around 500 m, while HD-SDI's camera-control signalling is unidirectional and cannot change camera settings.2 A PTZ command travelling up the same pair as the video is a command channel; it is not a network one.
These cameras have no address, no listening service and no credential store, so they cannot be enumerated and a defect in one cannot receive a CVE of its own. They are not software-free. An analogue-HD camera runs SoC firmware for the ISP pipeline, the OSD menus and the coax-control handling. That firmware is not remotely reachable, so it is also not remotely patchable, and no scan will ever tell you what is on it.
Why the cable stays#
Distance, mostly, and civils. One coax run reaches roughly 500 m in the AHD, HD-CVI and HD-TVI material; Nextchip's own AHD page claims transmission of 100 m and more and refers to ranges in the hundreds of metres. The upgrade is a camera and a head-end on cable that is already in the wall, against re-pulling through an occupied hospital corridor, a listed façade, or a plant where every penetration is a permit.
The resolution arithmetic supports the same decision. 1920×1080 is about five times the pixels of the 704×576 PAL 4CIF raster that Techpoint's receivers still decode alongside it — a real gain, bought without touching the containment. A site cabled in 2005 therefore takes a head-end swap in 2016 and another in 2026, and the coax outlives both. The decision is made on the cost of the builder's work.
The recorder is the whole estate#
Because the cameras are not network devices, everything remotely reachable on the site is one appliance — and that appliance is also the whole replacement decision. An unsupported IP camera can be segmented, fronted by something that can authenticate, or swapped one for one. Retire a coax recorder and the cameras go with it. They have no interface that speaks to anything else, and there is no second consumer for the signal.
The management plane is shared with the IP line regardless of what the front end terminates. CVE-2021-33045, the Dahua authentication bypass sent as "ipAddr": "127.0.0.1" with "loginType": "Loopback", was tested against IPC, VTH, VTO, NVR and DVR firmware older than early-to-mid 2020 — the coax recorder inherits the login logic of the IP one. CISA added it to the KEV catalog on 21 August 2024, nearly three years after public disclosure.
Tarlogic's teardown of a Dahua NVR and XVR, published 1 December 2025, found that "the bootloader is not signed" and that "encryption keys are accessible or derivable within the bootloader". The team needed physical access — the UART debug interface, an interrupted boot, a desoldered NAND dump — so this is not a remote path. It is a statement about what reflashing proves: restore vendor firmware to a recorder compromised below the signature check and you have proved nothing.
The white-label boards that Mirai's scanner found are covered in Mirai and the camera industry; what matters here is that those boards are the ones still terminating coax.
Hybrid recorders are not dual-homed enough#
An XVR takes coax channels and IP channels in one chassis. The standard advice is to treat it as dual-homed and plan the segmentation around it. That is necessary and it is not sufficient, for two reasons sitting on opposite faces of the box.
On the IP side, the recorder does not need an inbound path to be reachable. Hunt.io's Operation CameraSwarm, disclosed 18 August 2026, reached 283 of the compromised Dahua devices through the Easy4IP cloud relay at easy4ipcloud.com:8800 — a serial number and nothing else, no routable address, no forwarded port — and reports that 89.4% of live serials required no authentication through that relay. A clean port-forward table is therefore not evidence, and neither is an external scan of the site's address. The setting that matters is P2P registration in the device's own network menu, and the only reliable way to know it is off is to read it on the box.
On the coax side there is nothing to authenticate. We found no vendor documentation for AHD, HD-TVI or HD-CVI describing camera authentication of any kind; the receiver decodes what arrives on the pair. Anyone with access to the cable — a ceiling void, a riser, a junction box on a car-park pole — can lift the camera off the run and put a signal source in its place, and the recorder will store it as that channel, at the right resolution, with the right timestamp. No log anywhere in the estate records the substitution. Tamper evidence for an analogue run is physical: gland seals, lid switches, a cable schedule someone maintains. A camera that cannot be enumerated also cannot be identified, and both halves come from the same missing feature.
What is not measured#
We could not find a published source establishing the installed ratio of analogue and hybrid estates to pure IP, in any country or sector, and scanning cannot supply one: a hybrid recorder's coax channels are invisible from the internet, so a scan sees one host whether it fronts four cameras or thirty-two. Shodan's per-port figures are labelled "banners", not unique hosts, with no stated collection window.
Counting is unreliable even where the devices do answer. On 7 February 2020 Censys found 9,362 hosts on 9530/tcp actually speaking the HiSilicon protocol, out of 188,989 with the port merely open — a twentyfold gap between the port count and the protocol-confirmed one. That population is not a coax population: of 137 responders Censys sampled, 100 had RTSP on 554 and 50 had HTTP on 80, which makes them video-over-IP devices. It is a methodological warning, not a measurement of this estate. Anyone quoting a size for the legacy CCTV estate is estimating, and should say so.
Notes
- Dahua's UK product pages render as JavaScript and return no specification text to a fetcher, so the HDCVI entry above rests on the product families the site's navigation names, not on a retrieved datasheet. Per-model signalling matrices — which coax formats a given XVR accepts — are not verified here. ↩
- Manuel Martinez, "Back to Basics: HD over Coax", Security Info Watch, 16 March 2018. Trade press, not a standards document; the same article gives AHD a maximum of 500 m "through the use of equalizers". ↩
Sources
- AHD™ — Analog HD Transmission (1st Gen product page). Nextchip, fetched 2026-09-05
- Products — HD-TVI receiver, transmitter and ISP chipsets. Techpoint Inc., fetched 2026-09-05
- Back to Basics: HD over Coax. Security Info Watch (Manuel Martinez), 2018-03-16
- HDCVI Recorders product navigation. Dahua Technology, fetched 2026-09-05
- Reverse Engineering Dahua NVR/XVR Devices and Breaking Their Boot Security. Tarlogic, 2025-12-01
- Operation CameraSwarm: Over 14,000 Dahua cameras compromised across Ukraine and Russia. Hunt.io, 2026-08-18
- Full Disclosure: Dahua authentication bypass (CVE-2021-33044, CVE-2021-33045). Seclists / Full Disclosure, 2021-10-06
- Known Exploited Vulnerabilities Catalog (JSON feed), catalogVersion 2026.09.04. CISA, 2026-09-04
- Probing the Xiongmai/HiSilicon SoC Vulnerability. Censys, 2020-02-07
- Data Status — Banner Analysis Report, port exposure deep dive. Shodan, 2026-09-03