CCTV Security Advisory
Cheap CCTV Can Cost More Than You Think
The Dahua breach is a reminder that cameras and NVRs are networked ICT systems. Price matters, but security, privacy, firmware support and maintenance matter too.
View Security Checklist

WHY THIS MATTERS FOR BUSINESSES

The problem in plain terms

A modern CCTV system is a networked ICT system. It has firmware, user accounts, remote access, storage and sometimes cloud or P2P connectivity. The Hacker News reported that researchers identified a campaign affecting more than 14,500 Dahua devices. The lesson applies broadly to any organisation buying or operating networked cameras.

The Dahua story highlights common CCTV risks: weak or reused passwords, old vulnerabilities, P2P remote access left enabled, internet-facing NVRs and devices that are installed once then rarely checked again. The reported attack paths included authentication-bypass vulnerabilities CVE-2021-33044 and CVE-2021-33045, both listed in the CISA Known Exploited Vulnerabilities catalog.

dahua-cybersecurity-vulnerability-exploit

Dahua and similar CCTV systems are popular because they are affordable, available and easy to deploy. That is not automatically a problem. The problem starts when a CCTV purchase is judged only by camera count, storage days and installation cost, without checking firmware support, remote access, passwords, network separation and long-term maintenance.

Why cheap CCTV can become expensive

Bottom line: cheap hardware is not always cheap after you include privacy exposure, firmware support, remote access risk and long-term maintenance. The right question is not only “How many cameras can we get for this budget?” It is also “Will this system remain private, supported and secure?” This is where MCRS helps clients evaluate hardware from both a cost and security perspective.

Who is affected?

Any organisation using networked cameras, DVRs or NVRs should pay attention: schools, clinics, hotels, offices, apartments, warehouses, shops, NGOs and SMEs. The highest-risk environments are those with old firmware, shared installer passwords, cloud/P2P viewing enabled, no documentation and no network separation.

Security gaps to check

P2P or cloud viewing is enabled by default

Remote viewing is useful, but it must be understood, restricted and documented.

Default passwords remain in use

Every camera, NVR and mobile account should have unique credentials and clear ownership.

Firmware is never updated

Unsupported or outdated firmware can leave known weaknesses exposed for years.

CCTV shares the main office network

Cameras should not sit freely beside business PCs, finance systems, guest WiFi and servers.

Quick CCTV Security Checklist

Use these checks before buying a new CCTV system or when reviewing an existing one.

1

Confirm support model

Know who will update firmware, maintain storage and respond when cameras fail.

2

Secure admin access

Change defaults, document admin ownership and remove installer-only dependencies.

3

Review remote viewing

Avoid exposing recorders directly online; document how mobile viewing is controlled.

4

Separate the CCTV network

Keep cameras away from sensitive office systems and guest WiFi where possible.

5

Document the installation

Keep IP addresses, usernames, warranty details, support contacts and handover notes.

Quick advice for business owners

Ask for documentation whenever CCTV is installed. Know who has admin access, who can view cameras remotely, how firmware updates will be handled and whether the CCTV network is separated from business systems. If you are unsure, get the setup reviewed before a small saving becomes a serious exposure.

What to ask before approving a CCTV quotation

Before approving a CCTV quotation, the cheapest hardware price should not be the only decision point. Ask these practical questions so the installation is secure, maintainable and accountable after handover.

Firmware support

Does the quote include updates for cameras, NVRs and mobile viewing apps after installation?

Credential ownership

Who owns the admin passwords, recovery email and installer accounts when the work is handed over?

Remote access method

Is viewing exposed directly to the internet, dependent on P2P cloud access, or controlled through a safer network design?

Network separation

Will cameras and recorders be separated from office computers, guest WiFi and sensitive business systems?

Maintenance responsibility

Who checks storage health, failed cameras, user access, time settings and evidence retrieval after go-live?

Documentation

Will you receive a handover document with IP addresses, usernames, support contacts and warranty details?

Need a second look at your CCTV setup?

MCRS can review camera and NVR configuration, remote access, passwords, network separation and maintenance risks before a small saving becomes a serious exposure.