Finite State finds 20-year-old vulnerabilities in wifi camera
Finite State researchers have found a 2026 consumer camera that’s been shipping with a web server vulnerability first disclosed more than 20 years ago...
...allowing attackers to access credentials and cloud tokens and potentially compromise cameras.
The research team identifies three critical vulnerabilities in the Wansview WVC Q5 indoor wifi camera, a low-cost device commonly marketed as a baby monitor, pet camera, nanny cam and home security camera.
Researchers identified three critical vulnerabilities, including a directory traversal flaw first disclosed in 2002 that exposed administrator credentials, cloud API tokens and configuration data. They also uncovered two unauthenticated denial-of-service vulnerabilities that, because of outdated software protections, could potentially lead to full device compromise.
Because the camera is based on a white-label firmware platform, AjCloud, used by multiple vendors, the researchers believe similar vulnerabilities could exist across numerous consumer camera brands.
Larry Pesce, vice president at Finite State, said: “The broader software supply chain problem facing connected devices is that vulnerable components can persist for decades when software inventories, SBoM programmes and continuous vulnerability monitoring are absent or incomplete.”
Pesce has published an overview at finitestate.io/blog/20-year-old-vulnerability-2026-home-camera and details the vulnerabilities discovered, supply chain risks and research methodologies at finitestate.io/resources/iot-camera-supply-chain-vulnerability-research.
Chinese firm Wansview (wansview.com) has since fixed the problem. Pesce said: “Wansview handled the disclosure well, and the response deserves as much attention as the flaw. Instead of leaving the unsafe component in place with a patch bolted on, the vendor removed the web server entirely and rebuilt the video feature around a design that no longer exposes the weak point, then delivered the fix to customers automatically over the internet. The update installs on its own whenever a camera is online, so owners had to do nothing to receive it, a better outcome than most consumer devices manage, where unpatched units sit in the field for years because no one thinks to check. That choice, to cut the attack surface out rather than paper over it, is the one the other brands on the same base ought to follow.”
IoT Newsdesk has asked Wansview to comment.
Finite State will be at next month’s Black Hat conference in Las Vegas showing how its security and product teams use firmware-grounded visibility, reachability-driven prioritisation and automated compliance workflows to reduce risk, accelerate vulnerability response and maintain continuous audit readiness. For more information, see finitestate.io/events/black-hat-2026.