New massive security whole in many dahua devices (ip-cam,vdp,...)!

Quick question - back in 2018 I purchased a few Dahua cameras from Empire Andy based on this forum's help. I noticed one of the cameras falls into this latest security bulletin. When I click into the camera and go to update the firmware via a manual check it says it has the latest firmware (dated 2018). On the Dahua website there is a ton of additional firmware files relevant to this series of camera - SD1A1. Should I download something from the Dahua site, or just let it go because maybe these are gray market with different firmware?
 
  • Like
Reactions: mat200
Quick question - back in 2018 I purchased a few Dahua cameras from Empire Andy based on this forum's help. I noticed one of the cameras falls into this latest security bulletin. When I click into the camera and go to update the firmware via a manual check it says it has the latest firmware (dated 2018). On the Dahua website there is a ton of additional firmware files relevant to this series of camera - SD1A1. Should I download something from the Dahua site, or just let it go because maybe these are gray market with different firmware?

These cameras can be updated with stuff on Dahua website, but if your camera is isolated from the internet, then there is no need to update it.

But to be safe, I would search this forum for the latest firmware on that camera that Andy posted.
 
These cameras can be updated with stuff on Dahua website, but if your camera is isolated from the internet, then there is no need to update it.

But to be safe, I would search this forum for the latest firmware on that camera that Andy posted.

Thanks - I don't port forward if that is what you mean. I use Blue Iris to view the cameras. UPnP is off. I don't see a P2P option. Anything else I should look at?
 
What about the rest of your internet? Is every device at home on the same 10.x.x.x. scheme and do the cameras go thru the router?

If so, you could do the child protect in the router to prevent them from accessing the internet.
 
What about the rest of your internet? Is every device at home on the same 10.x.x.x. scheme and do the cameras go thru the router?

If so, you could do the child protect in the router to prevent them from accessing the internet.
Yes all devices 10.x.x.x scheme and cameras go through the my PoE switch which is plugged into my Mikrotik router. I can look at those settings (its like a foreign language) to see if I can do some sort of prevention from accessing the internet.
 
  • Like
Reactions: user8963
Quick question - back in 2018 I purchased a few Dahua cameras from Empire Andy based on this forum's help. I noticed one of the cameras falls into this latest security bulletin. When I click into the camera and go to update the firmware via a manual check it says it has the latest firmware (dated 2018). On the Dahua website there is a ton of additional firmware files relevant to this series of camera - SD1A1. Should I download something from the Dahua site, or just let it go because maybe these are gray market with different firmware?
How to Secure Your Network (Don't Get Hacked!) | IP Cam Talk
 
How you use Blue Iris remotely? I have to use VPN to use UI3. That is the correct way, right?
 
VPN and either UI3 or the BI app on an Android phone here.
 
  • Like
Reactions: tibimakai
Thanks all - I have UPnP off, Port Forwarding off and I don't use a VPN but as mentioned I use Blue Iris. I'll update the firmware from Andy as listed above too just to be safe.
When you say you use BI --- you mean when you are at home on your LAN-- right? If you are viewing it away from home, then you have your network open and vulnerable to the outside. You need some kind of VPN for encrypted access to your LAN when you are away from home.
 
When you say you use BI --- you mean when you are at home on your LAN-- right? If you are viewing it away from home, then you have your network open and vulnerable to the outside. You need some kind of VPN for encrypted access to your LAN when you are away from home.
I am using BI remotely via their encryption at or at least I assumed (maybe incorrectly) that there was some level of encryption/security on the end of BI. I do have a VPN that I use for other tasks, I guess I could not let BI speak to the outside world and just turn on my VPN then open the BI app.