VideoCybersecurity

A reference for securing video infrastructure

DVR security

What the recorder's supply chain and its remote-access defaults do to remediation, and why a DVR cannot be retired the way a camera can.

Published 5 September 2026Sources 17

On Shodan's port snapshot of 3 September 2026, the top product string on 37777/tcp is "Dahua XVR" — a recorder.1 Shadowserver has run a standing daily scan of 37810/UDP for years and called the output the Open DVR DHCPDiscover report.2 Two of the instruments behind published video-exposure numbers are aimed, by their own labelling, at recorders.

How much of the rest is recorders, nobody has measured. No public dataset separates the two at scale, and the fingerprints that would do it — an HTTP login page, an RTSP banner — belong to both. So treat the claim that "exposed camera" counts are substantially recorders as an inference from the port evidence rather than a measurement. It matters because the two are not the same remediation problem, which is where this page ends.

A badge with no board behind it#

The board inside an unbranded recorder came from an ODM that built firmware on a silicon vendor's reference code, and the brand on the bezel may have had no hand in either — the division of labour is set out on the camera page. XiongMai is the worked example. Flashpoint found the Mirai credential root/xc3511 hardcoded into its white-labelled DVR and IP-camera boards and, on 6 October 2016, counted more than 515,000 systems showing signs of running that hardware.3 It sat behind telnet and SSH in firmware and was not feasibly changeable from the web admin panel. That story is told in full on Mirai and the camera industry; it is the case with contemporaneous reporting behind it, though the underlying scan was private research. The 2020 telnet backdoor on TCP 9530, which HiSilicon's own PSIRT scoped to HiSilicon-based DVRs and cameras and blamed on code "delivered by equipment vendors", is quantified on the firmware page.4

What no page carries is the shape of the segment those cases came out of. OpenIPC's processor listing catalogued 126 SoC models across 14 vendors as of 5 September 2026: SigmaStar 30, Ingenic 27, HiSilicon 23, then Goke 13, Fullhan 12 and a long tail. Eighty of the 126 come from the first three.5 Novatek publishes no public SoC security documentation — no secure-boot description, no OTP or signing scheme — and the same holds for SigmaStar, Ingenic, Goke and Fullhan. The substantive public material on those platforms is community reverse engineering.

For the ODM and white-label recorders built on them, no vendor security documentation could be located at all: no firmware-signing statement, no advisory page, no support window, no contact for reporting a defect. Absence of documentation is not proof the features are absent. It does mean there is no published commitment to hold a supplier to, and nowhere to send a finding.

CISA's catalogue shows the terminal state. KEV 2026.09.04 holds 1,695 entries, 83 of which carry a required action that is not to patch but to stop using the product. Among the video entries, the two NUUO NVRmini/NVRmini2 flaws and the two Reolink ones — all four added 18 December 2024 — plus D-Link's DCS-930L carry that language: actively exploited, no remedy available.6

A buyer can act on this before the purchase and barely at all after it. Bosch, which does publish, defines a firmware platform "mainly by the used system-on-chip (SoC)" and dates its milestones per platform rather than per model.7 That is the unit to ask about: which SoC, which platform, when that platform first shipped, where its advisories live. Where the model is identifiable, camerarisk.com keeps its defect history per model.

What the recorder puts on the internet#

A recorder that will be watched from a phone needs a path inbound, and there are two on offer: a forwarded port, or the vendor's cloud relay. How devices end up with the first is its own subject. What lands on the internet is largely unregistered:

PortIANA registrationRole on these devicesDated observation
554/tcprtspMedia transport328,470 banners on Shodan's 2026-09-03 snapshot; Modat counted 545,947 RTSP services on 554 in March 2026
8554/tcprtsp-altAlternate media transport159,056 banners, 2026-09-03
37777/tcpnoneDahua's proprietary SDK and management port98,592 banners, 2026-09-03; top product "Dahua XVR"
37810/udpnoneUDP/JSON DVR management, particularly DahuaShadowserver runs a daily report, amplification around 25, and publishes no count

Neither 37777 nor 37810 appears in the IANA registry, which is why both are vendor conventions rather than services.8 Their identity comes from scanning research: Censys names 37777 as Dahua's proprietary SDK and management port, and finds Amcrest strings on it because Amcrest hardware is Dahua-derived.9 The RTSP rows carry Modat's warning that only 56.06% of the 973,819 services it found in March 2026 sat on 554, tabulated per country on the exposure page.10 Hunt.io reached 283 Dahua devices in Operation CameraSwarm through the Easy4IP cloud relay on nothing but a serial number.11 Nobody has measured how many recorders are reachable that way, so every figure in the table above undercounts by an unknown factor.

What the exploitation record shows#

GreyNoise watched exploitation attempts against TVT NVMS9000 recorders climb from 31 March 2025, peaking above 2,500 unique source IPs on 3 April and totalling more than 6,600 over the preceding 30 days, roughly triple the usual level, with enough overlap between IPs to attribute the activity to Mirai. The source IPs concentrated in Taiwan (3,637), Japan (809) and South Korea (542); those are the countries the scanning came from.12 That is attacker interest, not exposure.

The bugs the interest rides on are cheap. CVE-2021-33044 and CVE-2021-33045 are trust-the-client logic flaws in Dahua's login handling — the CCTV page gives the actual JSON payloads — and 1,923 of the CameraSwarm devices fell to that pair.13 None of the 22 video entries in KEV 2026.09.04 is flagged as used in known ransomware campaigns, though whether that reflects reality or a gap in CISA's attribution data for embedded devices cannot be settled from the catalogue.14

The clearest documented ransomware involvement runs the other way round. In the Akira case S-RM investigated, the actor entered through a remote access solution, had the Windows encryptor quarantined by EDR, then found a webcam running a lightweight Linux with command execution and no endpoint agent, and ran the Linux build from there against SMB shares.15 The camera served as the execution host; entry had happened elsewhere. A recorder is the same kind of host with more disk on it.

An unsupported DVR is not an unsupported camera#

An end-of-life IP camera is a bounded problem. Segment it, deny it a default route, put a recorder or VMS in front of it, swap it one for one — every option exists because the camera is an endpoint and the recording happens elsewhere.

On a coax site the recorder is the recording, the retention, the viewing client, the account store and the only device the cameras can talk to. Segment it hard enough to be safe and the remote access it was installed to provide goes with it. Retire it and the analogue cameras go too, having no interface that speaks to anything but that chassis. The CCTV page attributes the survival of legacy coax estates to cabling economics; this asymmetry sits on top of that and pushes the same way.

The published clocks are shorter than buyers assume. Dahua's end-of-life policy, last modified 27 October 2025, commits to security updates "for at least 2 (TWO) years after the first shipment for sale of certain Dahua Products" — a clock that starts before the box reaches the buyer.16 Hikvision's equivalent commitment we could not establish: its cybersecurity pages return a JavaScript challenge rather than the document, and we will not characterise a policy we have not read. Reflashing is not a dependable fallback either, since Tarlogic found the bootloader unsigned on the Dahua DHI-NVR2104-4KS2 and DH-XVR4104HS-I, covered on the NVR page.17

Close the forward and terminate remote access somewhere that can authenticate a user. Turn off P2P registration in the device's own network settings, which the forward does not cover. None of that buys back a support window. Where the recorder is unsupported and the cameras are analogue, the remaining fix is replacing the head end, often the cabling with it — a capital line, not a patch cycle.

Notes

  1. Shodan Data Status, 3 September 2026. The column counts banners, not unique hosts, over an undefined collection window.
  2. Shadowserver, Open DVR DHCPDiscover Report, page last updated 11 December 2023. It describes 37810/UDP as a UDP-based JSON protocol used to manage networked DVRs, particularly Dahua-brand, and notes responses can arrive from 37810 even when the scan targets 37777. Counts appear only on the dashboard, which Shadowserver forbids scraping.
  3. Brian Krebs, 21 October 2016, reporting Flashpoint's scan: private research, not a government determination.
  4. Huawei PSIRT security notice, released 5 February 2020, holding that the fault lay not in HiSilicon's chips and SDKs but in code delivered by equipment vendors — the SoC vendor's own account. Censys measured the population on 7 February 2020: 9,362 hosts speaking the HiSilicon protocol on 9530/tcp, out of 188,989 with the port open.
  5. OpenIPC processor listing, fetched 5 September 2026. Coverage reflects community reverse-engineering effort, not market share, and the page makes no claim about abandoned firmware.
  6. KEV catalogVersion 2026.09.04. The required action reads: "The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product."
  7. Bosch IP Video Firmware Info Brief, publishing date 20 February 2026. It is a living document versioned by publishing date only, so its platform rows move; re-fetch before citing a specific one.
  8. IANA service name and transport protocol port number registry, fetched 5 September 2026: 554 is rtsp, 8554 is rtsp-alt, and 37777 and 37810 have no entry.
  9. Censys, "Hunting Cameras in the Dark", page dated 10 March 2026; Censys blocks scripted fetches, so the date comes from the rendered page. The counts in it are snapshots at time of writing, not global aggregates.
  10. Modat, March 2026 scan; no credentials tested, no authentication bypassed. Its publication date is inconsistent: research index 1 March 2026, press release 9 June 2026.
  11. Hunt.io, 18 August 2026, on a 35-day campaign; 89.4% of live serials required no authentication through the relay. The devices measured are cameras.
  12. GreyNoise, 7 April 2025. It publishes no count of exposed devices, and states the observed IPs were malicious and non-spoofable.
  13. "bashis", Full Disclosure, 6 October 2021. CVE-2021-33045 was tested against IPC, VTH, VTO, NVR and DVR firmware older than early-to-mid 2020; CVE-2021-33044 has a different firmware window. CISA added both to KEV on 21 August 2024.
  14. KEV catalogVersion 2026.09.04, 1,695 entries, of which 22 resolve to a video product under the rule set out in camera cybersecurity.
  15. S-RM, 5 March 2025. It names no CVE and no camera vendor, and its own timeline does not support the common secondary description of ransomware entering via a webcam.
  16. Dahua Product End-of-Life Policy, page last modified 27 October 2025. Milestone entries carry EOS dates of 31 December 2026, 2027 or 2029 by product category; the policy does not apply to products whose lifecycle has already ended.
  17. Tarlogic, 1 December 2025; physical access via UART and a desoldered NAND dump, with encryption keys accessible or derivable in the bootloader. No CVE or vendor response is stated.

Sources

  1. Data Status — Banner Analysis Report, port exposure deep dive. Shodan, 2026-09-03
  2. Open DVR DHCPDiscover Report. The Shadowserver Foundation, page last updated 2023-12-11
  3. Hunting Cameras in the Dark: Finding Internet Cameras Before Adversaries Do. Censys, 2026-03-10
  4. Service Name and Transport Protocol Port Number Registry. IANA, fetched 2026-09-05
  5. Internet-Exposed RTSP: A Global Analysis. Modat, March 2026 scan
  6. Operation CameraSwarm: Over 14,000 Dahua cameras compromised across Ukraine and Russia. Hunt.io, 2026-08-18
  7. GreyNoise Observes 3X Surge in Exploitation Attempts Against TVT DVRs — Likely Mirai. GreyNoise, 2025-04-07
  8. Known Exploited Vulnerabilities Catalog (JSON feed), catalogVersion 2026.09.04. CISA, 2026-09-04
  9. Hacked Cameras, DVRs Powered Today's Massive Internet Outage. Krebs on Security, 2016-10-21
  10. Technical Analysis Report on the Suspected Security Issue of HiSilicon Video Surveillance Chips. Huawei PSIRT, 2020-02-05
  11. Probing the Xiongmai/HiSilicon SoC Vulnerability. Censys, 2020-02-07
  12. Processors — supported SoC vendors and models. OpenIPC, fetched 2026-09-05
  13. IP Video Firmware Info Brief. Bosch, 2026-02-20
  14. Dahua authentication bypass disclosure (Full Disclosure mailing list). bashis, via seclists.org, 2021-10-06
  15. Camera off: Akira deploys ransomware via webcam. S-RM, 2025-03-05
  16. Product End-of-Life Policy. Dahua, last modified 2025-10-27
  17. Reverse Engineering Dahua NVR/XVR Devices and Breaking Their Boot Security. Tarlogic, 2025-12-01