How cameras end up on the internet
The routes by which a camera becomes reachable from outside, and why every published exposure figure measures only some of them.
Modat counted 973,819 RTSP services answering on the internet in a March 2026 scan. Shodan's public port page reported 328,470 banners on 554/tcp on 3 September 2026. The distance between those two numbers is definitional rather than empirical: one publishes what it counted and how, the other labels its column "Banners" and never says what a banner is.
What the two have in common matters more than the gap. A scanner reaches a device only if that device answers at a routable address, so both figures — and every other figure below — count one class of route onto the internet and are silent about the rest.
The routes, and which ones a scan can see#
A gateway forward is the deliberate route. Hikvision's US support portal tells installers that direct IP remote access needs TCP 80, TCP 8000 for the mobile app and iVMS-4200, and TCP 554 or 10554, all of which "can be customized".1 Dahua prints TCP 37777 and UDP 37778 as its own defaults in the Web 3.0 manual.2 Checked against the IANA registry on 5 September 2026, 37777, 37778 and 37810 have no registration at all, which is why scanners fingerprint them by payload rather than by lookup.3 Port numbers and shipped states across five vendors are on camera ports and protocols.
UPnP produces the same result without an administrator. Hikvision's own hardening guide describes it as "a networking protocol that enables automatic port forwarding on routers", states that UPnP is disabled by default on its network cameras as of the 2025 edition,4 and Axis has disabled UPnP (TCP/49152) and SSDP (UDP/1900) from AXIS OS 12.0.5 The Axis change is version-gated, so an 11.x fleet still answers.
Vendor P2P moves reachability out of the gateway configuration entirely. Cloud video security carries the Hik-Connect port list and Dahua's own definition of the feature; camera network segmentation carries the audit consequence, along with the Bosch platforms whose closed-port defaults do not survive a firmware upgrade.
The first two leave an inbound mapping and a routable address behind them, so a scanner finds those devices and every count below is a count of them. Relay-reachable devices hold neither. We found no published measurement of that population, and no published breakdown of exposed devices by route of any kind.
What is actually measured#
There is no authoritative, continuously-published count of internet-exposed cameras and recorders. There is a handful of scans whose definitions and denominators do not line up.
Modat's is the most methodologically explicit of them. Its March 2026 internet-wide measurement identified 973,819 active RTSP services across 210 countries and 12,970 autonomous systems, of which 854,997 (87.8%) were still reachable at verification time. 477,539 had decodable video. 8,074 — 0.83% of the starting set — returned a live frame with no credentials required, and Modat states that "No credentials were tested. No authentication was bypassed."6 One IP exposed 358 sequential feeds.
Only about 4% of the services returned a recognisable product string, and Modat notes that more than a third of the ones it did fingerprint were not camera devices. The publication date is also inconsistent: modat.io's research index lists the post as 1 March 2026, the accompanying press release is dated 9 June 2026, and the scan itself is described as March 2026. We could not resolve which is right.
Two denominators from the same platform#
Modat publishes a second, larger figure from the same product: 3,359,886 RTSP endpoints, of which 797,153 hosts presented an RTSP service alongside a Hikvision login page, with Axis at 5,047 hosts, Reolink 4,902, Wisenet NVR 2,703 and Amcrest 987. Vendor attribution there comes from a co-located HTTP interface on the same host, not from the RTSP banner. Modat also tagged 7,972 of those hosts as OT, 2,918 as ICS and 1,086 as SCADA.6
3,359,886 and 973,819 are not the same measurement and must not be quoted against each other — the second is the verified-active subset, the first is the endpoint population. Coverage that treats them as interchangeable produces a Hikvision exposure figure with no denominator attached to it.
The port-coverage problem#
Only 56.06% of those services (545,947) ran on port 554. 427,872 — 43.9% — ran on something else, spread across 10,671 distinct ports.6
| Country | On port 554 | On other ports | Share on 554 |
|---|---|---|---|
| Taiwan | 151,389 | 7,434 | 95.3% |
| China | 111,977 | 32,550 | 77.5% |
| United States | 55,243 | 40,223 | 57.9% |
| Russia | 28,711 | 63,158 | 31.3% |
| Spain | 5,365 | 36,653 | 12.8% |
The national spread is wide enough that a 554-only sweep is close to a census in one country and close to useless in another, so any exposure figure should arrive with its port list. Next most common after 554 were 555 (24,515), 8554 (12,847) and 556 (12,352). See camera ports and protocols.
Where the open streams are#
The 0.83% global no-credential rate is not evenly spread. Iran held 1,268 viewable streams — 15.7% of all viewable streams worldwide — from 91,869 responsive services, a 1.38% hit rate, alongside 171 in Israel, 150 in Ukraine and 33 in Belarus. Conflict-affected countries together held 1,626 viewable streams, roughly one in five of the global total, at a 1.29% hit rate against 0.76% across the rest of the world.6
The other published counts#
| Source | Published | Figure | Unit |
|---|---|---|---|
| Modat6 | March 2026 scan | 973,819 RTSP services; 8,074 viewable | Services, own scan, 10,671 ports |
| Shodan7 | 2026-09-03 | 328,470 on 554/tcp; 159,056 on 8554; 98,592 on 37777 | "Banners" — not defined as hosts |
| Bitsight TRACE8 | 2025-06-10 | over 40,000 accessible cameras, ~14,000 US | Cameras reached and fingerprinted; a floor |
| Bitsight9 | 2023-03-09 | 1 in 12 tracked orgs susceptible; ~1 in 4 in education | Organisations, not devices |
| Censys10 | 2026-03-10 | 1,393 hosts on 37777 matching "Amcrest"; 680+ Dahua with anonymous access | Snapshot queries, not aggregates |
| Top10VPN11 | scans Sept 2021 | 6.3M networks outside China (4.8M Hikvision, 1.5M Dahua) | "Networks" by unique IP |
| PAM 201812 | data Sept–Oct 2017 | 28,386 unique active unprotected cameras over 18 days | A directory listing; a lower bound |
Shodan labels the column "Banners" and does not define whether that is a host, a host:port, or a record in a collection window, and gives no collection interval.7 That is not a caveat on the comparison with Modat's 545,947 services on 554 — it is what makes the comparison impossible.
Two widely-recirculated numbers need dating before use. CYFIRMA's ~80,000 Hikvision devices vulnerable to CVE-2021-36260, drawn from a 285,000-server sample and reported on 22 August 2022, is four years old; the sample's collection date is not stated in any source we could retrieve, and CYFIRMA's own whitepaper was not reachable.13 Rapid7's "approximately 3 million internet-facing Hikvision devices" is a live Shodan query matching the HTML string /doc/page/login.asp, so it carries no measurement date and matches a login page rather than a confirmed device class.14
What nobody has counted#
- P2P-reachable devices. Nothing quantifies how many cameras are reachable through Easy4IP, Hik-Connect, TUTK/Kalay or equivalents. Hunt.io's Operation CameraSwarm, disclosed 18 August 2026, reported 14,530+ Dahua cameras compromised over 35 days: 12,324 unique IPs brute-forced on TCP 37777, 1,923 through the CVE-2021-33044/33045 authentication-bypass chain, and 283 through the Easy4IP relay, a path needing only a device serial number.15 Hunt.io's components are counted in different units — unique IPs for the brute-force set, devices for the relay set — so the total is the source's arithmetic, not ours. The 283 relay cases needed no routable address, so no IP-based scan would have counted them.
- ONVIF services. No published count exists. Shadowserver's Accessible WS-Discovery Service Report found 17,621 servers on 3702/udp as of 14 March 2023 but does not attribute them to ONVIF cameras.16 ONVIF's own device and media services run over HTTP on arbitrary ports, indistinguishable from any other web service without a SOAP probe. See ONVIF security.
- VMS platforms. Nothing from Shodan, Censys, Shadowserver or academia for Milestone, Genetec, ZoneMinder, Blue Iris or Frigate.
- DVR exposure by vendor. Shadowserver's daily Open DVR DHCPDiscover report on 37810/UDP, last updated 11 December 2023, publishes no number on the page.17 Its Device Identification Report classifies devices into a taxonomy that includes a
video-systemclass, so a per-vendor daily population does exist — inside a dashboard whose terms permit attributed use but forbid scraping, which means the figure has to be requested from Shadowserver rather than lifted from it.18
Notes
- What port forwards are required for direct IP remote access? — Hikvision Support Portal, 10 October 2022. Four years old; re-verify against current firmware. ↩
- Dahua Network Camera Web 3.0 Operation Manual V2.0.1, section 4.6.2, Table 4-23 (2019-11-11). ↩
- IANA Service Name and Transport Protocol Port Number Registry, CSV fetched 5 September 2026. 554 is
rtsp, 8554rtsp-alt, 3702ws-discovery; 37777, 37778 and 37810 return no row. ↩ - Hikvision Network Security Hardening Guide, ©2025. Configuration paths in it are based on a camera device of version 5.7; the default it states carries no firmware boundary. ↩
- AXIS OS Hardening guide, retrieved 5 September 2026. ↩
- Internet-Exposed RTSP: A Global Analysis — Modat, March 2026 scan. ↩
- Shodan Data Status, port exposure deep dive, snapshot 3 September 2026, out of 227.5M total banners. ↩
- Bitsight TRACE, 10 June 2025. The 78.5% HTTP / 21.5% RTSP split reached publication via The Register, not Bitsight's page; circulating absolute HTTP and RTSP counts are arithmetic on "over 40,000", not measurements. ↩
- Bitsight press release, 9 March 2023, 54 countries. An organisation-level rate, not comparable to the 2025 device count. ↩
- Hunting Cameras in the Dark — Censys. Date read from the rendered page; Censys blocks scripted fetches, so treat it as probable. ↩
- Top10VPN, scans September 2021, updated 16 November 2021. An upper bound on installations and a lower bound on cameras. ↩
- Xu, Xu & Chen, PAM 2018. Port 80 carried 32.8% of admin interfaces, non-standard 60001 about 15%. The active set is at most 5.1% of all cameras that directory ever listed. ↩
- Reported by BleepingComputer, 22 August 2022, across 2,300 organisations in 100 countries. Per-country counts unconfirmed against a primary source. ↩
- Rapid7 Analysis: CVE-2021-36260, page dated 16 June 2026, updated 15 July 2026. ↩
- Operation CameraSwarm — Hunt.io, 18 August 2026, after CERT notification on 10 August 2026. Hunt.io reports 89.4% of live serials required no authentication through the relay. ↩
- Accessible WS-Discovery Service Report — Shadowserver, as of 14 March 2023. ↩
- Open DVR DHCPDiscover Report — Shadowserver, page last updated 11 December 2023. ↩
- Announcing the Device Identification Report — Shadowserver, 8 September 2021. ↩
Sources
- Internet-Exposed RTSP: A Global Analysis. Modat, March 2026 scan; index date 2026-03-01, press release 2026-06-09
- Data Status — Banner Analysis Report, port exposure deep dive. Shodan, 2026-09-03
- Bitsight Identifies Thousands of Compromised Security Cameras. Bitsight TRACE, 2025-06-10
- Peep show: 40K IoT cameras worldwide stream secrets to anyone with a browser. The Register, 2025-06-10
- Bitsight identifies thousands of global organizations using insecure webcams and other IoT devices. Bitsight, 2023-03-09
- Hunting Cameras in the Dark: Finding Internet Cameras Before Adversaries Do. Censys, 2026-03-10 (probable)
- Global Locations of Hikvision & Dahua Surveillance Cameras. Top10VPN, scans September 2021; updated 2021-11-16
- Over 80,000 exploitable Hikvision cameras exposed online. BleepingComputer, 2022-08-22
- Rapid7 Analysis: CVE-2021-36260. Rapid7, 2026-06-16, updated 2026-07-15
- Internet Protocol Cameras with No Password Protection: An Empirical Investigation. Xu, Xu & Chen — PAM 2018, data collected 2017-09-25 to 2017-10-12
- Operation CameraSwarm: Over 14,000 Dahua cameras compromised across Ukraine and Russia. Hunt.io, 2026-08-18
- Accessible WS-Discovery Service Report. The Shadowserver Foundation, figure as of 2023-03-14
- Open DVR DHCPDiscover Report. The Shadowserver Foundation, page last updated 2023-12-11
- Announcing the Device Identification Report. The Shadowserver Foundation, 2021-09-08
- What port forwards are required for direct IP remote access?. Hikvision Support Portal, 2022-10-10
- Hikvision Network Security Hardening Guide. Hangzhou Hikvision Digital Technology Co., Ltd., 2025
- Network Camera Web 3.0 Operation Manual V2.0.1. Dahua Technology, 2019-11-11
- AXIS OS Hardening guide. Axis Communications, retrieved 2026-09-05
- Service Name and Transport Protocol Port Number Registry. IANA, fetched 2026-09-05