Ouch, I own a few of these cameras. I chose Amcrest because they have a local US distributer who does all of the technical/warranty support. Interesting.
At this point you can't trust any 'cloud' camera regardless of who makes it.
"Non-cloud" cameras that secrety use cloud are also a problem.
Why ouch? If they are local-only the max mischief they might cause is relatively limited, right? Or do you suspect them of phoning home behind your back?
I have a handful of 'local-only' chinese import cameras (although no Dahuas). They all reach out to hard-coded IP addresses on the chinese mainland. (with no explanation why, nor a setting to turn it off) I put them on a dedicated VLAN without internet access for this reason.
google VLAN hopping
I inspect the traffic. The devices I have don't speak 802.1Q at all.
I haven't seen any unusual communication from any installed, but they're all firewalled and with WAN disallowed. The ouch was because I will have to find another vendor if they are no longer allowed to be sold in the US.
Those companies are only disallowed from use in government.
That was previously the case. This[0] announcement is that these[1] devices from these[1] manufacturers will not receive FCC authorization for use in the US moving forward.