Junglewise Threat Intelligence

CVE-2024-51348: BS Producten Petcam stack overflow in P2P API service

CVE-2024-51348 · Severity: high · CVSS 8.8 · Published 2026-03-25

Executive brief

A security vulnerability has been identified in BS Producten Petcam devices, which are smart cameras used for remote monitoring. An attacker within wireless range or on the same local network can take complete control of the camera without needing a password. This could allow an unauthorized person to view live video feeds, disable the device, or use it as a foothold to attack other devices on the home or business network.

Technical details

A stack-based buffer overflow (CWE-121) exists in the P2P API service (listening on port 8001) of BS Producten Petcam firmware version 33.1.0.0818. The vulnerability is located in the URI parsing logic where the application extracts a resource string and concatenates it with a local path string into a fixed-size 260-byte stack buffer without length validation. An unauthenticated attacker on the local network or within range of the device's default unencrypted 'local mode' Wi-Fi access point can exploit this by sending a specially crafted HTTP request. Successful exploitation allows the attacker to overwrite the instruction pointer and achieve Remote Code Execution (RCE) with root privileges, as the binary lacks modern exploit mitigations.

Affected products

  • BS Producten Petcam 33.1.0.0818

Timeline

  • 2026-03-25: advisory: NVD publication date

References

Related threats