Ah now this is an example of why uPnP should absolutely ALWAYS be turned off - the CCTV system will just do everything it thinks it needs to work and really doesn't care about any unintended consequences. I cannot see any valid reason why it would need the SNMP ports opened to the internet - unless of course someone, possibly the manufacturers intend to remote control and/or monitor it!
So what I would do is go into the Hub settings as above, make a note of the ports that have been opened, then disable uPnP. Reboot the hub to drop any established connections and then manually set up port forwarding for the ports EXCEPT for 161.
What I would be tempted to do is add the ports one at a time and test if the CCTV still works - after all do you want port 80 (unencrypted HTTP connections) allowed into your network without a very good reason? No, me neither! 443? probably yes - but see what works and what doesn't.