Nooie baby monitors have zero-day vulnerabilities that might allow video stream hijacking
Researchers were able to perform remote code execution (RCE) on two of Nooie's Baby Cam newborn monitoring devices. Other devices in the same range may be susceptible as well, although this has yet to be proven.
On the Google Play Store, the Nooie Cam app has between 50,000 and 100,000 downloads, indicating that the technology is extensively utilized."Hijacking the video stream is usually a major emotional effect for the customer from a privacy viewpoint," Dan Berte, director of IoT security at Bitdefender, said. "But RCE might also lead to denial of service, cryptomining, ransomware, or data exfiltration - equally serious, if not more."
The flaws were discovered as part of Bitdefender's larger study, which aims to assist "vendors and customers remain on top of security and privacy blind spots and make the IoT ecosystem safer for everyone." Read More