Junglewise Threat Intelligence

CVE-2025-69988: BS Producten Petcam incorrect access control in Local Mode Wi-Fi

CVE-2025-69988 · Severity: medium · CVSS 6.5 · Published 2026-03-27

Executive brief

The BS Producten Petcam, a smart camera used for remote monitoring, contains a security flaw in its 'Local Mode' configuration. When this mode is active, the camera creates an open Wi-Fi network that does not require a password. Anyone within physical range of the device can connect to this network to view live video and audio streams, leading to a significant breach of privacy and physical security.

Technical details

The BS Producten Petcam (version 33.1.0.0818) fails to implement authentication when operating in 'Local Mode'. In this state, the device broadcasts an unencrypted Wi-Fi Access Point (SSID pattern CLOUDCAM_[MAC]) with no WPA encryption. An attacker within wireless range can associate with the network and receive an IP address via DHCP. Once connected, the attacker has direct access to the camera's internal services, including the RTSP stream on port 554 and a custom API on port 8001, neither of which require credentials. This vulnerability also serves as a prerequisite for further exploitation of other vulnerabilities requiring network adjacency.

Affected products

  • BS Producten Petcam 33.1.0.0818

Timeline

  • 2026-03-27: disclosed: Initial disclosure of CVE-2025-69988
  • 2026-03-27: advisory

References

Related threats