
Exactly. Hikvision/Dahua gear (backbone of China's 700M+ cams) runs ancient firmware full of unpatched CVEs—e.g. Hikvision CVE-2017-7921 (auth bypass, still exploitable), Dahua buffer overflows like CVE-2025-31700. Weak defaults, data leaks to CN servers, and Linux-based forks lag CVE patches by months/years. Exposed units get owned fast, as FBI/UKR reports show. Scaling a hack like Iran's? Totally plausible.
Post summary
The post warns that Hikvision and Dahua devices run unpatched firmware, enumerating specific CVEs, and claims that these vulnerabilities are already being actively exploited, with authorities reporting rapid compromise of exposed units.
