Common camera ports and protocols
A reference table of camera, VMS and discovery ports, with the shipped state vendors print and the widely repeated numbers that could not be confirmed.
TCP 37777 answering on a camera VLAN is a Dahua-family device. The port is unregistered, so scanners fingerprint it by payload rather than look it up. TCP 4520 is Wisenet. TCP 8000 is more ambiguous than it looks — it is Hikvision's SDK service on an embedded device, and it is also what Milestone's Mobile Server uses for its SysTray app, so the same integer means different things on a camera and on a Windows host. Axis has no proprietary control port at all: VAPIX and ONVIF both ride 80 and 443, which is why an Axis fleet leaves no distinctive number behind for a scanner to key on.
Protocols and their default ports#
| Protocol | Default port | What it carries | Authentication | Where the default is printed |
|---|---|---|---|---|
| RTSP | 554/tcp and 554/udp | Stream setup and playback | RFC 2326 §16: "Servers SHOULD implement both basic and digest" | RFC 2326 §9; IANA rtsp |
| RTSPS | 322/tcp | RTSP inside TLS | As RTSP | IANA rtsps; RFC 7826 §10.2 |
| RTSP alternate | 8554/tcp | As 554 | Vendor's choice — the LSC Smart Connect Indoor (CVE-2024-51362) and Vivotek IP7137 (CVE-2025-66049) shipped it unauthenticated | IANA rtsp-alt; RFC 7826 §10.2 |
| HTTP / HTTPS | 80, 443 | Web UI, ONVIF SOAP, vendor HTTP APIs | Vendor-set | AXIS OS hardening guide; Dahua Table 4-23 |
| ONVIF device service | None assigned | SOAP device management at the fixed path /onvif/device_service | Digest under Core v26.06 and Profile T; optional on the device under Profile S, where WS-UsernameToken is mandatory instead | Core v26.06; Profile S v1.3 §7.1.1; Profile T v1.0 |
| WS-Discovery | 3702/udp, to 239.255.255.250 and FF02::C | Hello, Probe, Resolve | None | WS-Discovery 1.1 §3.1.1 |
| SSDP (UPnP) | 1900/udp, to 239.255.255.250 | Discovery and router port mapping | None | UPnP Device Architecture 1.1 |
| mDNS / Bonjour | 5353/udp | Name and service announcement | None | AXIS OS hardening guide (enabled by default) |
| Multicast video (Dahua) | Group 224.1.2.4 — main 40000, sub-streams 40016 and 40032, selectable 1025–65500 | Multicast copies of the streams | As RTSP | Dahua manual §4.6.9, Table 4-28 |
| RTMP | 1935/tcp | Push to a streaming service | Vendor-dependent | Dahua manual Table 4-23 |
| iSCSI | 3260/tcp | Camera storage as a target, and the camera's own outbound client path on the same number | Target-dependent | Bosch "Secure by default" |
| NTP | 123/udp | Time | — | Bosch |
ONVIF fixes the path, not the port; read the port from XAddrs or GetNetworkProtocols. The Dahua multicast row bites on a shared segment: the group and all three port numbers are identical on every unit out of the box, so camera two lands where camera one already is.
Outbound cloud connectivity — Hik-Connect, Dahua P2P, ONVIF Uplink — puts devices out of reach of both these tables; that is covered in how cameras become internet-exposed.
Vendor ports, and what ships enabled#
| Vendor | Ports the vendor documents | Shipped state the vendor states | Source and date |
|---|---|---|---|
| Hikvision | Server Port 8000 (SDK/private protocol, range 2000–65535), HTTP 80, RTSP 554 or 10554, Alarm Host 7200, Enhanced SDK Service 8443 (TLS) | ONVIF, UPnP and SSH each "disabled by default"; Enhanced SDK Service and Security Mode enabled, plain SDK Service to be left off | "Configure Port" package, 2023-04-10; Hardening Guide, 2025. The 10554 alternate is from a 2022-10-10 support article and should be re-verified against current firmware |
| Dahua | TCP 37777 and UDP 37778 (DVRIP private SDK), HTTP 80, HTTPS 443, RTSP 554, RTMP 1935 | SSH shipped as a toggleable System Service alongside CGI, ONVIF and a dedicated Genetec Service listener; "The ONVIF authentication is On by default"; Mobile Push "is enabled by default" | Web 3.0 Manual V2.0.1, §4.6.2 Table 4-23, §4.8.5.1, 2019-11-11 |
| Axis | No proprietary control port. VAPIX and ONVIF share 80/443; RTSP 554; RTSPS listed as 332 in the audio white paper | HTTPS enabled with a self-signed certificate since AXIS OS 7.20; UPnP (49152) and SSDP (1900) off from 12.0; WS-Discovery off from 12.1 | AXIS OS hardening guide, retr. 2026-09-05; audio white paper 2024-06 |
| Hanwha Vision | Device port 4520 (SVNP), HTTP 80, HTTPS 443, RTSP 554 | No remote-shell daemon at all — §3.4 "Remote service (Telnet, SSH) not used"; SUNAPI and ONVIF restricted until a password is set | IP Camera Network Hardening Guide V4.0, §§3.4, 3.11, 5.7, 2023-04 |
| Bosch | RCP+ 1756, HTTP 80, RTSP 554, iSCSI 3260, NTP 123 | All five closed at factory default, staged: CPP13 fw 8.90 (July 2023), CPP14 fw 9.10 (March 2024), CPP7.3/7/6 with the 7.89 release (June 2024) | "Secure by default" TechNote, 2024-03 |
Remote shell is where the vendors diverge most sharply. Hanwha says it removed the daemons; Hikvision ships SSH present and disabled, adding that "For devices without this configuration interface, SSH is disabled by default"; Dahua ships it as a user-toggleable service in the same panel as ONVIF and CGI. Axis documents SSH as supported from AXIS OS 5.50 and recommends disabling it.
Three gaps, stated rather than filled. Bosch names only "RCP+ ports 1756" and refers to "the discovery ports" without printing their numbers; the 1757/1758 pair repeated across integrator forums appears in no Bosch-authored document we could fetch, and Bosch's knowledge base has moved to keenfinity-group.com with the old URLs returning shells or 404. Hikvision's "Configure Port" page lists Alarm Host, Server, HTTP, RTSP and Enhanced SDK but no HTTPS port, so 443 is not citable as a Hikvision default from it. And Axis's audio white paper prints RTSPS as 332 where Genetec documents the IANA-registered 322 for secure RTSP to cameras — Axis choice, product-line difference or typo, we could not resolve it.
Two qualifications on the Bosch row. On CPP14 and the CPP6/7/7.3 family, a fleet upgraded in place keeps RCP+, HTTP and RTSP as it had them: "New defaults will not automatically become effective during a firmware upgrade but require a factory default to be applied." Only CPP13 at firmware 8.90 takes the new defaults on upgrade. Two of the five closures are also inbound-only — the iSCSI client "uses the same port 3260 in 'outgoing' direction, which is still open", and a camera with its NTP server shut is "still listening on port 123 to synchronize its time base".
Dahua's note above Table 4-23 reads: "0-1024, 1900, 3800, 5000, 5050, 9999, 37776, 37780-37880, 39999, 42323 are occupied for specific uses." The manual advises against assigning them without stating that the device enforces it. 37776 and the 37780–37880 block sit immediately beside the documented 37777/37778 pair, so a sweep of 37777 alone undercounts.
VMS servers answer on camera ports#
| Server or role | Port | What it carries |
|---|---|---|
| Milestone Recording Server | TCP 7563 | Video and audio streams and PTZ commands — the client-to-recorder video path |
| Milestone Recording Server | TCP 5432 | Device event messages. Documented disabled by default, and it collides with the registered PostgreSQL port |
| Milestone Recording Server | UDP 65101; SMTP 25 | Event notifications from the device drivers; SMTP disabled by default and deprecated |
| Milestone Recording Server | TCP 5210, 8966, 11000, 12975; HTTP 9001 | Failover database merge, service status, state polling, SNMP extension agent, inter-server web service |
| Milestone Event Server | TCP/UDP 1234, TCP 1235, TCP 9090; TCP 22331, 22333 | "Generic events from external systems or devices" and analytics events — unauthenticated by design, straight into the VMS event pipeline |
| Milestone Management Server | 80, 443, TCP 6473, 8080, HTTP 9000, TCP 12345, 12974 | Authentication and configuration; 12345 for Matrix recipients; 12974 SNMP extension agent |
| Milestone Mobile Server | HTTP 8081, HTTPS 8082; TCP 8000 | Video and audio data streams; 8000 is the SysTray app |
| Milestone Open Network Bridge | TCP 580, RTSP 554 | 580 authenticates and configures the stream; 554 serves the video to ONVIF clients |
| Genetec Directory | TCP 5500 (TLS 1.2) | Inbound from every role; outbound from Security Desk and Config Tool |
| Genetec Archiver | TCP 5551, 6051 | Live and playback stream requests; 6051 for edge playback |
| Genetec Archiver | UDP 15000–19999 inbound; UDP 47806–47807 | Live unicast video per ArchiverAgent, each additional agent starting 5,000 higher; 47806–47807 multicast, listed inbound and outbound on both sides |
| Genetec Media Router / Media Gateway | TCP 554; TCP 654 plus 80/443 | Inbound RTSP to the Router; the Gateway serves RTSP clients on 654 |
Three of those rows answer RTSP on a Windows server: Milestone's Open Network Bridge on 554, Genetec's Media Router on 554, the Media Gateway on 654. The 5432 row is the trap most likely to survive into a report, because a scanner labelling ports from the IANA registry will call an XProtect recording server a database host. And 15000–19999 is five thousand ports wide before you count the second Archiver agent, which is why camera-VLAN egress rules get written loosely.
The Milestone numbers come from the 2020R3 documentation, roughly six years old as of September 2026; the current ports page returned only the portal shell, so verify them against your own release. The Genetec figures span two pages — 5.13 for the port list, 5.9–5.12 for the firewall guidance — and where they disagree we could not determine which supersedes the other.
Why the list is a starting point#
Ports move, and the vendors say so. Hikvision states its three remote-access ports "can be customized" and gives the Server Port a range of 2000–65535. Hanwha's guide tells the installer to raise 80, 443, 554 and 4520 to high numbers, then warns in the same section that doing so "may cause communication problem if there is a connected recording device or VMS".
So scan wider than the defaults. RTSP alone has three registered numbers — 554, 322 and 8554 — plus Hikvision's 10554, and both unauthenticated-RTSP CVEs above were on 8554. Enumerate services per device and record the answer against the asset; that is the discipline the Video Attack Surface Management framework is organised around. Protocol detail on RTSP sits on the RTSP page, ONVIF's authentication model on ONVIF security.
Sources
- Configure Port — product documentation. Hikvision, 2023-04-10
- What port forwards are required for direct IP remote access?. Hikvision Support Portal, 2022-10-10
- Hikvision Network Security Hardening Guide. Hangzhou Hikvision Digital Technology Co., Ltd., 2025
- Network Camera Web 3.0 Operation Manual V2.0.1. Dahua Technology, 2019-11-11
- AXIS OS — Hardening guide. Axis Communications, retrieved 2026-09-05
- Network requirements for Axis network audio. Axis Communications, 2024-06
- IP Camera Network Hardening Guide V4.0. Hanwha Vision, 2023-04-18
- Secure by default: Increasing the default level of IP camera security. Bosch, 2024-03
- Ports used by the system — XProtect 2020R3. Milestone Systems, 2020R3
- Default ports used by Security Center 5.13. Genetec, retrieved 2026-09-05
- Opening firewall ports for Security Center communication. Genetec, Security Center 5.9–5.12
- RFC 2326 — Real Time Streaming Protocol (RTSP). IETF, 1998-04
- RFC 7826 — Real-Time Streaming Protocol Version 2.0. IETF, 2016-12
- Service Name and Transport Protocol Port Number Registry. IANA, fetched 2026-09-05
- ONVIF Core Specification v26.06. ONVIF, 2026-06
- ONVIF Profile S Specification v1.3. ONVIF, 2019-11
- ONVIF Profile T Specification v1.0. ONVIF, 2018-09
- Web Services Dynamic Discovery (WS-Discovery) Version 1.1. OASIS, 2009-07-01
- UPnP Device Architecture 1.1. UPnP Forum, 2008-10-15
- CVE-2024-51362. NVD, 2024-11-05
- CVE-2025-66049. NVD, 2026-01-09