...."Discovered by Ankit Anubhav, Principal Researcher at NewSky Security, a cyber-security company specialized in IoT security, these passwords are for Dahua DVRs running very old firmware that is vulnerable to a five-year-old vulnerability."
....
"A quick search from Bleeping Computer has unearthed a worrisome number of vulnerable devices. For example, we found nearly over 15,800 Dahua devices with a password of "admin", over 14,000 with a password of "123456," and over 600 with a password of "password". That's around 30,000 Dahua devices running older firmware and ready for the taking, and we found them with just three queries"