← The Signal Report Work with me

Report 060 · Luxury Home Security

When your security camera has a critical flaw and no patch is coming

The comforting version goes: a researcher finds a flaw, the vendor ships a patch, you install it. Four camera advisories published by CISA over the past year break that chain at four different links. In two of them the vendor simply never answered, and the official remediation is a phone number.

A camera is the only thing on an estate's security plan that is also a computer with a support lifecycle. A gate is a gate for thirty years. A safe is a safe. A camera is a small networked Linux machine that depends, permanently, on a company somewhere continuing to care about it.

Most security advice handles this with one word: patch. Keep firmware current, and you're fine. I want to test that advice against what actually gets published, because the U.S. government maintains a public record of exactly these flaws, and reading a year of it is more instructive than any buyer's guide.

What a CISA advisory is

The Cybersecurity and Infrastructure Security Agency publishes ICS advisories: a researcher reports a vulnerability, CISA attempts to coordinate with the manufacturer, and the advisory goes out with the technical details and a remediation section. Each carries a CVSS severity score, where 9.0 and above is critical.

The remediation section is the interesting part, because it records what the vendor did. Here are four camera advisories, and four different ways "just patch it" falls apart.

One: nobody is home

Advisory ICSA-26-176-05, released June 25, 2026, covers the H.VIEW HV-500S6 IP camera. Two vulnerabilities: CVE-2026-55975, an OS command injection through the certificate generation interface that can run commands with elevated privileges, and CVE-2026-56414, an unrestricted file upload letting an authenticated user write arbitrary content to persistent filesystem locations, which CISA notes "could affect system integrity or behavior even after reboot." Both are scored 7.2 on CVSS v3.1 and 8.6 on v4.0. Deployment is listed as worldwide.

The entire remediation reads:

"H.View did not respond to CISA's request to coordinate. Users are encouraged to reach out to H.View for support."

That is the fix. Call them yourself. An advisory exists, the flaw is public and now indexed by everyone who reads these feeds, and the mitigation is a contact page.

Two: nobody is home, and you can't tell if you're affected

Advisory ICSA-25-343-03, last revised February 5, 2026, covers multiple India-based CCTV cameras. CVE-2025-13607 is scored 9.4, critical: "A malicious actor can access camera configuration information, including account credentials, without authenticating when accessing a vulnerable URL."

Two of the three vendors responded properly. D-Link India published a security announcement and a software update. Securus released firmware dated 15-12-2025. That is the system working.

The third entry is different. For Sparsh Securitech the remediation field reads "None available," with the note that the vendor "did not respond to CISA's requests for coordination." And the advisory's own product list says the specific affected models "are not available."

Sit with that combination. There is a critical, unauthenticated credential-disclosure flaw. There is no patch. And there is no list of which of that vendor's cameras have it, so an owner cannot even determine whether they are exposed. CISA's advice is to contact your representative and ask.

Three: the product is already dead

Advisory ICSA-26-048-04, last revised March 12, 2026, covers Honeywell HIB2PI CCTV cameras. CVE-2026-1670 scores 9.8, near the top of the scale: "an unauthenticated API endpoint exposure that may allow an attacker to remotely change the 'forgot password' recovery email address."

Notice the mechanism, because it is elegant and it is not a break-the-encryption story. The attacker does not defeat your password. They redirect the account recovery path, then use the front door as designed. I made this point about smart locks and it keeps proving out: strong cryptography sitting next to a weak account-management path is not a secure system, it is a secure component in an insecure system.

Honeywell's remediation notes that "The affected product has been discontinued since April 2025" and directs users to contact customer service for patch information. A discontinued product with a 9.8 is the ordinary case, not an exotic one. Cameras get installed and then outlive their product lines by a decade.

Four: the patch costs you the feature you bought

Advisory ICSA-26-148-06, released May 28, 2026, covers KMW CCTV cameras, headquartered in Romania, deployed worldwide. CVE-2026-5386 scores 9.1: "a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password to a known value without authentication, granting full access to the camera feeds and settings."

This time there is a real fix. KMW issued firmware. The system worked end to end.

Then read the next line in the advisory:

"KM-IP421 - will lose the cloud authorization after this update so users will need to contact customer support to re-authorize the P2P connection."

The patch closes a critical hole and, as a side effect, kills remote viewing until the owner calls support and gets the connection re-authorized. Every honest security practitioner knows what happens next for most installations. The camera keeps working, the phone app keeps working, and the update waits for a better week that never arrives. A patch with a usability penalty has a lower real-world install rate than a patch without one, and the gap between "a fix exists" and "the fix is running on your wall" is where the actual risk lives.

What CISA actually recommends

Here is what I find most telling. The standing "Recommended Practices" block on every one of these advisories is not about patching at all. It is architectural:

"Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices."

The agency publishing the vulnerability leads with segmentation, not with updating. That is the right instinct, and it is the same instinct that governs how you handle a threat you cannot fix at the source. You cannot compel a Chinese or Romanian manufacturer to answer an email. You can absolutely decide what your camera is allowed to reach.

In counter-IED work the pattern is familiar in mirror image. When a countermeasure could not defeat a device, the answer was to change the environment the device operated in rather than to keep improving the countermeasure. Here the device you cannot fix is your own. Same move: stop trying to make the endpoint trustworthy and start constraining what an untrustworthy endpoint can do.

The sentence that means less than it sounds

Every one of these advisories closes with a line worth parsing carefully:

"No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time."

Four qualifiers in one sentence. No known exploitation, that has been reported, to CISA, at this time. It is an accurate statement about the contents of an inbox. It is not a statement about whether anyone is using the flaw, and it should never be read as reassurance. Silence in a reporting channel is not evidence of absence, it is evidence that nobody wrote in.

The same inversion applies to the advisories themselves, and it is the point I would most want an estate owner to take away. An advisory existing for a brand means a researcher looked at that brand and a process ran. A brand with no advisories has not been proven clean. It may simply be that nobody has audited it, which is the more common condition for cheap cameras.

What this does and does not prove

I want to be careful about scope, because the easy version of this article would be scarier and less true.

These are ICS advisories covering commercial and prosumer equipment, not a survey of consumer doorbell cameras. Two of the four are listed as deployed worldwide; the Honeywell and India-based advisories list India as the deployment area. Nothing here says a specific camera on a specific wall is vulnerable, and I am not claiming your system is compromised.

What the record does establish is structural, and it holds regardless of brand. Patching a camera depends on a vendor you do not control, a product line that may already be discontinued, a model list that may not exist, and an update that may cost you a feature. Four advisories in about eight months, each breaking the chain at a different link, is enough to say the failure is systemic rather than anecdotal.

For a large property that matters more than for an apartment, because the numbers work against you. An estate may run dozens of cameras from several brands, specified by an integrator during construction, commissioned once, and never revisited. Nobody in that chain is tracking CVEs on your behalf after the final invoice. And a compromised camera is worse than a blind one: it is a foothold on your network with a view of your routines, which is precisely the reconnaissance material the crews targeting these homes want, and it pairs badly with an address that is already purchasable.

The practical version

None of this requires becoming a network engineer. It requires four decisions, all of which are cheaper before installation than after.

Know what you own. A written inventory of every camera, model, firmware version and install date. You cannot check advisories against equipment you cannot name, and most owners genuinely cannot name theirs.

Put cameras on their own segment. A separate VLAN or physical network, no route to the internet unless a specific device needs one, and no path from a camera to the machines that hold anything that matters. This is the single highest-value change, and it is the one CISA leads with.

Record locally, always. Cloud-dependent recording fails for boring reasons as readily as dramatic ones, which is the whole argument of the subscription gap. Local storage also means a camera that has been isolated from the internet still does its primary job.

Ask the end-of-support date before you buy. Not the warranty. The date the manufacturer stops issuing firmware. If a vendor will not answer that question in writing, you have learned something useful about how they will handle a 9.8 in year six.

Designing that layer, the part that decides what a device is allowed to reach and how fast a real event gets recognized as real, is the work I do on the security side, and I'll be exact about my role: I help design the AI security systems for a veteran-owned (SDVOSB) home-security company run by fellow veterans. I don't own that company and earn nothing from this link; I flag it because it's a field I build in, not just write about. Full policy here.

The signal

Every camera you install is a bet that a company you will never speak to keeps caring about a product it has already sold you. Sometimes that bet pays: D-Link and Securus shipped fixes, KMW shipped firmware within weeks. Sometimes the remediation field says "None available."

You cannot control which kind of vendor you drew. You can control whether that matters. Design the network so that a camera going bad is a camera problem rather than a house problem, and the vendor's silence stops being your emergency.

Sources

  1. Cybersecurity and Infrastructure Security Agency, "H.VIEW HV-500S6 IP Camera," ICS Advisory ICSA-26-176-05, released 25 June 2026. (PRIMARY. Retrieved and text-extracted locally; cisa.gov returns 403 to ordinary automated fetches. Source for CVE-2026-55975 and CVE-2026-56414, their descriptions, the CVSS v3.1 7.2 and v4.0 8.6 scores, the worldwide deployment listing, and the verbatim remediation stating H.View did not respond to CISA's request to coordinate. Vulnerabilities reported to CISA by Fukuhara Rikuto of Smooth Inc. and Hosei University.)
  2. Cybersecurity and Infrastructure Security Agency, "Multiple India-based CCTV Cameras (Update A)," ICS Advisory ICSA-25-343-03, last revised 5 February 2026. (PRIMARY. Retrieved and text-extracted locally. Source for CVE-2025-13607, its verbatim description, the CVSS v3.1 9.4 critical score, the D-Link India and Securus fixes, the "None available" remediation for Sparsh Securitech with the verbatim non-response note, and the advisory's statement that specific affected models for that vendor are not available.)
  3. Cybersecurity and Infrastructure Security Agency, "Honeywell HIB2PI and HDZ Series CCTV Cameras (Update B)," ICS Advisory ICSA-26-048-04, last revised 12 March 2026. (PRIMARY. Retrieved and text-extracted locally. Source for CVE-2026-1670, its verbatim description of the unauthenticated recovery-email change, the CVSS v3.1 9.8 critical score, the India deployment listing, and the verbatim statement that the product has been discontinued since April 2025.)
  4. Cybersecurity and Infrastructure Security Agency, "KMW CCTV Security Cameras," ICS Advisory ICSA-26-148-06, released 28 May 2026. (PRIMARY. Retrieved and text-extracted locally. Source for CVE-2026-5386, its verbatim description, the CVSS v3.1 9.1 critical score, the Romania headquarters and worldwide deployment listing, the firmware fix, and the verbatim note that the KM-IP421 loses cloud authorization after the update and requires contacting customer support to re-authorize the P2P connection.)

The "Recommended Practices" and "no known public exploitation" passages quoted here appear verbatim in the standing blocks carried by all four advisories. Scope note: these are ICS advisories covering commercial and prosumer equipment, and the deployment areas are as listed above. This report makes no claim about the security of any consumer camera brand not named in these advisories, and the absence of an advisory for a brand is explicitly not evidence that the brand is secure.

Onur Oncer
Onur Oncer

U.S. Army combat veteran (Counter-IED / Electronic Warfare), peer-reviewed researcher in microwave spectroscopy, and founder & CEO of Shroombiosis. Consults on laboratory operations, AI, and supplement formulation.

← All reports