Bitdefender has published a post detailing some security concerns surrounding Wyze (Wyze Labs), a good option for budget smart home gear. Typically, these kinds of issues don’t cause concern to users – an organization reports a vulnerability to the company, the manufacturer takes action to close it, and once it’s safe, that first team can report its findings. In this case, Bitdefender actually waited for Wyze to patch the vulnerabilities in its gadgets – it took three years for any action to be taken.
See also: Hive ransomware: Uses new trick to hide payload

Smart cameras are a sensitive subject due to their importance in a household. They are often used to monitor children, yards, and other rooms in the home, which means they collect data that really shouldn't end up in the hands of attackers.
According to Bitdefender, the team wanted to report its findings after 90 days — the typical timeframe most infosec experts wait before publishing their research. Smart home gear can be very dangerous, as it often gives potential attackers access to a camera and microphone right inside your home. The company contacted Wyze in March 2019, but by June — the end of that 90-day window — nothing had been fixed.
See also: Zero-day in Java Spring allows remote code execution
The vulnerabilities reported by Bitdefender are as serious as you could imagine for a smart camera manufacturer. While Wyze cameras require an authentication process to connect, this group was able to bypass it completely, gaining full access to the device. This includes the ability to turn the camera on or off, disable SD card recording, and “tilt and pan” on supported devices.

Note that the researchers were unable to bypass the encryption of the live feed to view ongoing activity, but a stack-based buffer overflow could allow live access when combined with authentication bypass – this is the worst-case scenario that could be carried out by a hacker. The third vulnerability could also allow attackers to view recordings from the SD card via an unauthorized connection to the webserver.
See also: Apple and Meta shared data with hackers pretending to be researchers
Wyze has patched these security holes — which is why Bitdefender has finally released its findings. But it’s certainly concerning that the team reported these vulnerabilities three years ago, only to have them remain unpatched. Even after the patches were released, not every Wyze user is safe — its older cameras are still vulnerable. If you’re still using a first-generation Wyze camera, you should ditch it and upgrade to a newer model as soon as possible. Support for this model ended in February and it won’t see future updates.
Information source: androidpolice.com
