Finite State finds 20-year-old vulnerabilities in wifi camera

Finite State researchers have found a 2026 consumer camera that’s been shipping with a web server vulnerability first disclosed more than 20 years ago...

June 29, 2026

...allowing attackers to access credentials and cloud tokens and potentially compromise cameras.

The research team identifies three critical vulnerabilities in the Wansview WVC Q5 indoor wifi camera, a low-cost device commonly marketed as a baby monitor, pet camera, nanny cam and home security camera.

Researchers identified three critical vulnerabilities, including a directory traversal flaw first disclosed in 2002 that exposed administrator credentials, cloud API tokens and configuration data. They also uncovered two unauthenticated denial-of-service vulnerabilities that, because of outdated software protections, could potentially lead to full device compromise.

Because the camera is based on a white-label firmware platform, AjCloud, used by multiple vendors, the researchers believe similar vulnerabilities could exist across numerous consumer camera brands.

Larry Pesce, vice president at Finite State, said: “The broader software supply chain problem facing connected devices is that vulnerable components can persist for decades when software inventories, SBoM programmes and continuous vulnerability monitoring are absent or incomplete.”

Pesce has published an overview at finitestate.io/blog/20-year-old-vulnerability-2026-home-camera and details the vulnerabilities discovered, supply chain risks and research methodologies at finitestate.io/resources/iot-camera-supply-chain-vulnerability-research.

Chinese firm Wansview (wansview.com) has since fixed the problem. Pesce said: “Wansview handled the disclosure well, and the response deserves as much attention as the flaw. Instead of leaving the unsafe component in place with a patch bolted on, the vendor removed the web server entirely and rebuilt the video feature around a design that no longer exposes the weak point, then delivered the fix to customers automatically over the internet. The update installs on its own whenever a camera is online, so owners had to do nothing to receive it, a better outcome than most consumer devices manage, where unpatched units sit in the field for years because no one thinks to check. That choice, to cut the attack surface out rather than paper over it, is the one the other brands on the same base ought to follow.”

IoT Newsdesk has asked Wansview to comment.

Finite State will be at next month’s Black Hat conference in Las Vegas showing how its security and product teams use firmware-grounded visibility, reachability-driven prioritisation and automated compliance workflows to reduce risk, accelerate vulnerability response and maintain continuous audit readiness. For more information, see finitestate.io/events/black-hat-2026.

Finite StateFinite State

Finite State is the Product Security Automation Platform that functions as an autonomous Product Security OS: design → verify → prove, grounded in what you ship.

Platform

Platform Overview
Ground Truth Inventory
Exploitability-Based Prioritization
Design-Time Architecture Security
Automated Evidence-Backed Compliance

Solutions

Device Manufacturers
Automotive
Medical Devices
Energy & Utilities
Government
Industrial

Resources

Blog
Resource Library
Webinars & Videos
Events
Documentation

Company

About Us
CareersHIRING
Press & News
Contact Sales
Media Inquiries
X

© 2026 Finite State. All rights reserved.

Privacy PolicyTerms of UseCustomer Terms and Conditions
Finite StateFinite State
Finite StateFinite State
Get a DemoGet a Demo