Backdoors in VStarcam cameras

Over the years, VStarcam cameras added various mechanisms meant to leak the authentication password. While the purpose is unclear, these cameras cannot be trusted to restrict access.

Almost Secure

As you might have noticed, I’ve been looking into VStarcam firmware lately. My analysis of 367 firmware branches found something astonishing: starting with approximately 2022 VStarcam has been systematically and intentionally undermining the security of their cameras, adding mechanisms designed to leak the authentication password. While we can only speculate about the reasons, it’s clear that these cameras cannot be trusted with access to the Internet. https://palant.info/2026/01/07/backdoors-in-vstarcam-cameras/

#security #iot #VStarcam #firmware

Backdoors in VStarcam cameras

Over the years, VStarcam cameras added various mechanisms meant to leak the authentication password. While the purpose is unclear, these cameras cannot be trusted to restrict access.

Almost Secure

I’m having some fun with VStarcam firmware, so why shouldn’t you? After downloading hundreds of their firmware updates I decided to document all these numerous proprietary formats. This even included figuring out a proprietary compression algorithm (not the one I asked about here a few days ago, that one is still a mystery).

https://palant.info/2025/12/15/unpacking-vstarcam-firmware-for-fun-and-profit/

#vstarcam #firmware #iot #IoTSecurity

Unpacking VStarcam firmware for fun and profit

VStarcam firmware comes in lots of varieties and occasional proprietary formats that binwalk cannot handle. This article documents the formats and unpacking methods.

Almost Secure
Security cameras vulnerable to hijacking

Millions of security cameras, baby monitors and "smart" doorbells let hackers spy on their owners.