field note

IP camera vulnerabilities: how cameras get hacked

How IP cameras actually get hacked: default credentials, known CVEs in old firmware, and exposed interfaces. The fixes, and how to hold them at fleet scale.

2026-08-19

IP cameras get hacked through three doors, in this order: default or shared credentials, known vulnerabilities in firmware that was never updated, and management interfaces exposed where they should not be. Exotic zero-days make headlines, but the compromises that actually happen at scale walk through doors that were documented, patched, or preventable years earlier.

That is worth taking seriously for a specific reason. A camera is a computer with a lens: it runs an operating system, serves a web interface, and sits on your network around the clock. Attackers rarely want the video. They want the foothold.

Can security cameras be hacked

Yes. Any camera still holding a default password, running firmware with published CVEs, or exposing its management interface to the internet can be compromised with public tooling and no particular skill. The practical question is not whether cameras can be hacked, it is which of those three conditions is true somewhere in your fleet right now, and the rest of this page is about closing them and keeping them closed.

The three doors, in order of traffic

Default and shared credentials. The Mirai botnet proved this at internet scale in 2016 by logging into IP cameras, CCTV DVRs, and recorders with a short list of factory default passwords, then using the herd to knock major services offline. Nothing about that technique has aged out. Fleets still ship with defaults unchanged, and even careful deployments drift into a different version of the same problem: one shared admin password across five hundred devices, known to every technician who has ever serviced the site, unchanged since installation. Not every vendor still ships a default: current Axis cameras have no factory password at all, and what the circulating credential lists get wrong about them is in the Axis camera default password post. Rotation is the fix, and rotation done carelessly breaks recording, which is why it so often goes undone. The safe sequence is covered in how to rotate camera passwords without breaking the VMS.

Known CVEs in old firmware. Security camera vulnerabilities are published, cataloged, and weaponized on a schedule. A few real entries make the pattern concrete:

  • CVE-2021-36260, an unauthenticated command injection in Hikvision cameras, scored 9.8 and was folded into botnet exploit kits after disclosure. It sits on CISA’s Known Exploited Vulnerabilities list.
  • CVE-2017-7921, a Hikvision authentication bypass that let anyone retrieve device credentials with a crafted request, was still being exploited years after the patch existed.
  • CVE-2021-33044 and CVE-2021-33045, authentication bypasses in Dahua devices, also landed on the KEV list while patched firmware sat unapplied in the field.

The lesson is not about any one manufacturer. Every vendor ships vulnerabilities, including the ones we support deeply. The difference between a fleet that shrugs off a CVE and a fleet that joins a botnet is almost always patch latency: the months or years between the fix existing and the fix being on the device. Published camera, NVR, and DVR CVEs, and which of those CISA lists as exploited in the wild, are on the camera CVE tracker.

Exposed interfaces. A camera management interface reachable from the internet is a standing invitation, whether it got there through deliberate port forwarding, a convenience peer-to-peer feature left enabled, or a firewall rule nobody remembers writing. Search engines that index internet-connected devices make discovery free. The 2021 Verkada incident showed the cloud-side version of the same door: credentials exposed online gave intruders working access to roughly 150,000 cameras inside schools, jails, and hospitals.

How a camera compromise unfolds in four stages. Stage one, an entry point: a default or shared credential, an unpatched CVE, or an exposed interface. Stage two, device foothold: the attacker runs code on the camera. Stage three, the split: either the camera is enrolled into a botnet, or the attacker pivots deeper into the network the camera sits on. Stage four, the cost: outages, spying, and an incident report. The entry points are the only stage the defender fully controls. how a camera compromise unfolds entry point default credential unpatched CVE exposed interface device foothold attacker code runs botnet duty camera joins attacks network pivot deeper into your LAN the cost outage, spying, IR the entry points are the only stage the defender fully controls
Everything to the right of the first box is the attacker's schedule. The first box is yours.

What hardening actually looks like

The defensive list is short and unglamorous, which is exactly why it works and why it goes undone across large fleets:

  1. Unique credentials per device, rotated on a schedule, with service accounts separated from break-glass access, and rotation verified against the recording path so the fix does not become an outage.
  2. Firmware held current against each vendor’s actual eligibility, not against a version string someone wrote in a spreadsheet during installation.
  3. Valid certificates and encrypted management traffic, because credentials sent in the clear are credentials shared with the network. Lifecycle details are in camera certificate management.
  4. No internet-reachable management interfaces, no convenience remote-access features left enabled, and cameras on their own network segment so a foothold stays a foothold instead of becoming a pivot.
  5. An inventory that matches reality, because the camera nobody remembers is the camera nobody patches.

None of this is controversial. All of it decays. Passwords age, a vendor publishes a new firmware track, a certificate expires, a technician forwards a port to finish a Friday job. Hardening has no end date. The posture has to be re-verified continuously, per device.

Holding the line across 500 cameras

At fleet scale the hard part is not knowing the list above, it is proving the list is still true on every device this week. MentatNOC does that continuously: credential rotation that never breaks monitoring, firmware campaigns in staged waves with automatic rollback, certificate lifecycles tracked ahead of expiry, and tamper detection when a device stops behaving like itself. Every check and every change lands in an audit log built so entries cannot be rewritten after the fact, which turns your hardening posture into something you can hand an auditor or an insurer rather than assert in a meeting. It monitors device health, not video. The full capability set is on the platform overview, and the fastest way to evaluate it is a live platform demo against a fleet shaped like yours.