Executive brief
The Amazon Cloud Cam is a legacy home security camera that has reached its end-of-life status. Due to the decommissioning of its supporting infrastructure, the device now defaults to an insecure pairing mode when powered on. This allows an unauthorized person in physical proximity to hijack the device's network connection, potentially leading to the interception or modification of data transmitted by the camera.
Technical details
The Amazon Cloud Cam suffers from an insecure device pairing vulnerability following the deprecation of its backend service infrastructure. When the device is powered on, it fails to connect to its original remote services and enters a default pairing state. In this state, an attacker within wireless range can bypass SSL pinning mechanisms to associate the camera with a malicious network. This enables the attacker to perform man-in-the-middle (MitM) attacks to intercept or modify network traffic. Because the product is end-of-life (EOL) as of December 2022, no patches will be released, and the recommended mitigation is to decommission the hardware.
Affected products
- Amazon Cloud Cam All versions
Timeline
- 2022-12-02: other: Product reached end-of-life status
- 2025-06-12: disclosed: Original publication date listed in advisory content
- 2025-07-17: advisory: Advisory published/updated via AWS security bulletins