Readit News logoReadit News
pkcsecurity · 3 years ago
What counts as “remote access”? Another device authenticated to Wi-Fi? Another device anywhere on the internet, with knowledge of the device ID? Another device anywhere on the internet with knowledge of email address?

These are vastly different criticality levels.

All the talk of IOCtl and assembly/bytes in the in the ButDefender report implies “another device on the Wi-Fi”, but I know wyze cams can be viewed over-the-Internet, ostensibly proxied via Wyze’s own servers, so maybe not?

thefarstar · 3 years ago
I really wish the open source community would work on an open firmware that supports these webcams. Security is one thing, Wyze recently start pushing the WyzeBeta iOS app, which seems to pivot users towards subscription for basic functions like viewing motion alerts. That’s kind of alerting too.
kelchm · 3 years ago
So in practice, to exploit this someone would have needed to have been connected to the same local network at some point in time.

Yes, it’s still a vulnerability and Wyze should have actually responded in a reasonable period of time, but this really doesn’t seem like something to lose sleep over.

RandyRanderson · 3 years ago
And I was just considering ordering a bunch of their gear. I guess I'll go with ring - what choice have I?
eternityforest · 3 years ago
I wish there was just a cheap craptastic RTSP camera brand like Amcrest that had ONVIF and MDNS, but didn't have any Uighur human rights issues.
tehlike · 3 years ago
you can flash rtsp firmware for v2, but doesn't work for V3.

V3 has amazing night vision though so this whole thing sucks.