Executive brief
The Foscam VD1 Video Doorbell transmits sensitive communication data, including login credentials for its video relay service, without encryption. This allows an attacker on the same network or with visibility into the network traffic to intercept video streams or hijack the manufacturer's server infrastructure to send unauthorized data. Such an exploit could lead to privacy violations through unauthorized video access and financial or operational impact on the service provider.
Technical details
The Foscam VD1 Video Doorbell (versions prior to V5.3.13_1072) fails to encrypt Session Description Protocol (SDP) data during the Real-Time Communication (RTC) handshake. This signaling layer leakage exposes ICE credentials (ice-ufrag and ice-pwd) and ICE candidates in cleartext. A network-positioned attacker can intercept these credentials to redirect video feeds or authenticate to Foscam's TURN/relay servers. This authentication allows the attacker to use the vendor's infrastructure as a proxy for arbitrary traffic. The vulnerability is addressed in firmware version V5.3.13_1072 and later by enforcing TLS for signaling.
Affected products
- Foscam VD1 Video Doorbell Before V5.3.13_1072
Timeline
- 2026-05-14: advisory
- 2026-05-14: disclosed