Foscam Security Cameras Full of Security Flaws

[UPDATED June 23 with comment from Foscam.]

We've said it before, and we'll say it again: Don't buy cheap Chinese-made security cameras, because their security may just be terrible.

The Foscam C2, one of the allegedly vulnerable models. Credit: Foscam/Amazon

(Image credit: The Foscam C2, one of the allegedly vulnerable models. Credit: Foscam/Amazon)

The latest evidence of this comes from Finnish information-security firm F-Secure. Yesterday (June 7), it released a report alleging that Foscam security cameras are full of vulnerabilities that could let them be easily taken over by hackers — and that Foscam doesn't seem to want to do anything about it.

Not only are Foscam-branded cameras at risk, F-Secure notes, but so are cameras made by Foscam but marketed under 13 other brand names, including Opticam, Thomson and Netis.

MORE: Best Wireless Home Security Cameras

The flaws are staggeringly bad. They include hard-coded remote-access passwords that cannot be changed by the user; a hard-coded file-transfer password that is blank, i.e., no password; hidden Telnet access; no limit on incorrect login attempts; configuration files that can be changed remotely; remote factory reset; and a firewall that doesn't completely work.

"An attacker can view the video feed, control the camera operation and upload and download files from the built-in FTP server," F-Secure's report said. "They can stop or freeze the video feed, and use the compromised device for further actions such as DDoS or other malicious activity."

F-Secure tested two models: the Foscam C2, a home model sold in the United States for about $80, and the Opticam i5 HD, a home model sold in Finland. All 18 possible vulnerabilities were found on the Opticam, but only some on the Foscam. F-Secure warns that the same flaws probably exist in other models.

"While only two models have been investigated, it is likely that many of these vulnerabilities also exist in other models throughout the company's product line, and in other products Foscam manufactures and sells under other brand names," the report said.

Foscam makes and sells both low-priced home security cameras and commercial security cameras used by businesses and retailers. Using one of the affected cameras could greatly endanger a company's computer network.

"If the device is in a corporate local area network, and the attacker gains access to the network, they can compromise the device and infect it with a persistent remote-access malware," F-Secure warned. "The malware would then allow the attacker unfettered access to the corporate network and the associated resources."

Unfortunately, there's not much that home users can do to protect themselves, other than not connecting the cameras to the internet, which kinds of defeats the purpose of an internet-connected security camera.

Changing the default username and password won't do much, because numerous hidden hard-coded backdoor access credentials will still be on the device.

Foscam's U.S. website has a guide to updating a camera's firmware, and states that all known flaws had been fixed as of June 3. But F-Secure said it had informed Foscam of the flaws several months ago, and added that, "to date no fixes have been issued by the vendor."

Tom's Guide has reached out to Foscam for comment, and we will update this story when we receive a response.

UPDATE: Foscam has responded to our inquiries.

"We've conducted a thorough review and fixed all issues with firmware upgrades where necessary," the company said in an emailed statement. "The 18 items cited in the report were actually so minor in nature as to be virtually non-existent. ... There were therefore zero reports of any security breaches ever occurring in any products used by customers, due to the extremely improbable nature of the exploits."

"Due to miscommunication between F-Secure and the third-party OEM partner they [F-Secure] first contacted about their research, the R&D team at Foscam was not contacted until after a report was released," the statement specified.

A detailed security advisory has been posted on the Foscam Mall website, and notes that customers can "download new firmware from http://www.foscam.com/downloads/index.html or update the firmware using [the] Foscam App."

TOPICS
Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

Latest in Home Security
The Silent Beacon Bluetooth panic button worn on a wrist next to a Fitbit
I tried a physical panic button for 48 hours — and this tiny device already makes me feel safer
Ring Battery Doorbell Plus
7 Ring video doorbell tips everyone needs to know
A Tesla Powerwall next to a utility meter on the exterior wall of a green house
I deal with major snowstorms every winter and these Powerwall batteries are a game changer in my home
A Ring Outdoor Cam Plus on an exterior wall
Ring's new Outdoor Cam Plus security camera offers 2K video, better night vision
EufyCam 2C Pro on desk
EufyCam 2C Pro review
An Arlo camera on a house with a Toms Guide Price Drop tag
Presidents' Day home security tech deals: I picked the 6 best starter sales from $60
Latest in News
A first look at Amazon's Fallout TV series coming to Prime Video
‘Fallout’ season 3 plans are reportedly being made — while season 2 is still filming
Surface Laptop 7 from the front
Amazon just gave Surface Laptop 7 a 'frequently returned' label — here's what's going on
New emojis with iOS 18.4 beta release.
iOS 18.4 beta brings 8 new emoji to your iPhone — here's all the new options
23andME box
23andMe has declared bankruptcy — here's how to delete your data now
half-life alyx
Latest Half-Life 3 rumors point to a 2025 release — and maybe pigs will fly
NFL Sunday Ticket logo for YouTube
NFL Sunday Ticket 2025 pricing revealed — and it's bad news
  • wilsonbradley
    Foscam - Stupid should have updated their firmware and supported their products.. Will never buy their brand again..
    Reply
  • bABOOZA69
    i own a foscam. what do i do now besides disconnecting? can i get a refund?
    Reply
  • ConfusedSpecialist
    Do these vulnerabilities exist if you have them connected behind a firewall without enabling internet access/upnp? Surely the firewall would block access given the types of vulnerabilities exposed here?
    Reply
  • Paul Wagenseil
    19809757 said:
    Do these vulnerabilities exist if you have them connected behind a firewall without enabling internet access/upnp? Surely the firewall would block access given the types of vulnerabilities exposed here?

    Reply
  • Paul Wagenseil
    What you're describing is probably the only safe way to operate these devices until Foscam releases a firmware update that fixes these flaws.
    Reply
  • ConfusedSpecialist
    Yeah I've always considered them to be open to vulnerabilities so have never had them connected directly. Fingers crossed they don't expose a firewalled network any other way...
    Reply
  • Paul Wagenseil
    Unverifiable update: It appears that the U.S. Foscam company has been emailing customers to clarify that this is a problem with the Chinese Foscam company. https://meh.com/forum/topics/foscam-camera-vulnerabilities
    Reply
  • frankinchi
    I can confirm the Foscam email, as I have received one as well. Also looks like they stopped sales on their website.
    Reply