A dark bullet camera on a stone wall beside a glass entrance at dusk, with a glowing golden network diagram running down the wall

A Camera Is a Computer Too – It Just Happens to Sit on a Pole

Over twenty years I have designed a great many camera systems. In our profession we still often talk about a camera as an “eye”: it has a lens and a field of view, and it sends the picture somewhere. Yet a modern IP camera or network video recorder is a fully fledged computer. It runs an operating system and has user accounts, passwords, encryption keys and network services. It can be attacked like any server – it is just that far fewer people are watching it.

In September, two news stories showed this from two sides: once from the network, and once physically.

The first case: a recorder that can be taken over from the network

On 15 September, the US cybersecurity agency CISA issued an advisory on Digital Watchdog’s VMAX DVR and NVR recorder families. It described six vulnerabilities, including credentials hard-coded into the software, missing authentication for a critical function and predictable session identifiers. Two were rated critical (CVSS 9.6). Anyone exploiting them takes over the recorder as an administrator: they can watch live and recorded video, change the configuration and use the recorder as a stepping stone to the rest of the network. The manufacturer has released fixed firmware.

For the designer, the most important detail is that, according to CISA, the attack requires reaching the device from the local network. That sounds reassuring at first, but that is exactly the lesson. If the recorder sits on the same network as the office computers, a single infected laptop is enough. “Not visible from the internet” does not mean “protected”.

The second case: a camera taken down from its pole

In mid-September, a hacker group published what it had found on a previously deployed Flock licence plate recognition camera. These devices operate on street poles in American cities. The camera ran Android 8.1 from 2017, with a security patch level that had not been updated for years. The researchers found an API key hard-coded into the software and shared across several applications. Combined with a camera’s MAC address, it could be used to query data about other Flock cameras from the manufacturer’s server. On top of that, the encryption key was stored on the very device whose data it was supposed to protect. The result: more than 27,000 video clips and around 1.6 million images, roughly three weeks of recordings.

The lesson here is different. A device in a public space will sooner or later end up in someone’s hands. So design has to account not only for network attacks, but also for someone taking the device down, carrying it home and dismantling it at leisure. If the keys to the whole system can then be extracted from a single device, that is a design flaw, not bad luck.

What is worth applying consistently

Neither case is exotic. Both rely on flaws for which established countermeasures have existed for years:

  1. A separate network for security systems. A dedicated VLAN or a physically separate network, with firewall rules. The camera should only be able to talk to the recorder or the video management server, with no route to the internet.
  2. Remote access only via VPN. No port forwarding on the router. The manufacturer’s “one-click” cloud (P2P) access should also be switched off unless it was a deliberate decision.
  3. Unique passwords, unnecessary services disabled. No device should keep its factory password. UPnP, Telnet and unused protocols should be switched off.
  4. The network socket is an entry point too. If someone plugs a laptop into an outdoor camera’s cable, it must not get access. Certificate-based 802.1X is the right answer here. MAC address filtering alone is not enough, since the camera’s MAC address is printed on its label. There should also be an alarm when a camera port loses its link.
  5. Firmware lifecycle. A device inventory with version numbers, and regular monitoring of the manufacturer’s security advisories. At procurement, it is worth asking how long the manufacturer will provide updates. From December 2027, the EU Cyber Resilience Act will require this of manufacturers.
  6. What is on the device can be lost. Keep as little data and as few secrets as possible on an outdoor camera. Recordings belong on the protected recorder, not on the camera’s memory card.

What I take away from this

In many organisations, the camera is the least supervised computer on the network: it is installed, configured, handed over, and then nobody touches it for years. The two September cases are not about a new type of attack. They show that the old flaws still work just as well. A security system becomes secure when the designer treats the camera not only as a field of view, but also as a network endpoint and as a physically accessible device.

Sources: CISA ICSA-26-258-01 · Hackaday · Tom’s Hardware

Gabor Horvath, security systems engineer

Gabor Horvath

Security Systems Engineer

Gabor Horvath is a security systems engineer with more than twenty years of experience in the design, installation and operation of security systems. He has worked for government institutions, diplomatic missions and organizations in EU and NATO environments.

Connect on LinkedIn →