Cybercriminals are actively selling remote access to tens of thousands of Chinese surveillance cameras on dark web marketplaces. The cameras remain unpatched against a critical vulnerability disclosed 11 months ago, creating a direct pathway for attackers to infiltrate organizational networks.
The affected devices include models from major Chinese manufacturers. Organizations running these systems have failed to apply available security patches, leaving the cameras exposed to remote code execution attacks. Threat actors exploit this negligence by gaining access to the devices and then selling credentials to other criminal groups.
The vulnerability allows unauthenticated attackers to execute arbitrary code on vulnerable cameras. Once compromised, these devices serve as entry points into corporate networks, hospitals, retail environments, and government facilities. The cameras often sit on internal networks with minimal monitoring, making them ideal beachheads for lateral movement toward more valuable systems.
The scale of the problem is substantial. Security researchers have identified tens of thousands of vulnerable devices still connected to the internet. Marketplace listings show access prices ranging from dozens to hundreds of dollars per device, depending on network positioning and organizational value. Some listings bundle multiple camera accesses together, targeting specific sectors or geographic regions.
Organizations using these cameras face immediate risks. Attackers can view surveillance feeds in real time, disable security monitoring, or pivot into backend systems managing access control and data storage. Hospitals become particularly vulnerable, as compromised cameras could allow attackers to locate servers, monitor staff movements, or disable emergency response coordination.
The 11-month window between vulnerability disclosure and active exploitation underscores a broader patching failure. Many organizations either lack inventory visibility into their surveillance infrastructure or deprioritize camera security compared to workstations and servers. This assumption that cameras pose minimal risk proves dangerously incorrect.
Mitigation requires immediate action. Organizations should identify all surveillance devices on their networks, apply available patches from manufacturers, and isolate cameras on dedicated network segments.
