Executive brief
The BS Producten Petcam, a smart camera used for remote monitoring, contains a security flaw in its 'Local Mode' configuration. When this mode is active, the camera creates an open Wi-Fi network that does not require a password. Anyone within physical range of the device can connect to this network to view live video and audio streams, leading to a significant breach of privacy and physical security.
Technical details
The BS Producten Petcam (version 33.1.0.0818) fails to implement authentication when operating in 'Local Mode'. In this state, the device broadcasts an unencrypted Wi-Fi Access Point (SSID pattern CLOUDCAM_[MAC]) with no WPA encryption. An attacker within wireless range can associate with the network and receive an IP address via DHCP. Once connected, the attacker has direct access to the camera's internal services, including the RTSP stream on port 554 and a custom API on port 8001, neither of which require credentials. This vulnerability also serves as a prerequisite for further exploitation of other vulnerabilities requiring network adjacency.
Affected products
- BS Producten Petcam 33.1.0.0818
Timeline
- 2026-03-27: disclosed: Initial disclosure of CVE-2025-69988
- 2026-03-27: advisory