Bitdefender researchers have discovered vulnerabilities in Nooie Baby Cam video baby monitors that could allow attackers to access video streams or execute malicious code on vulnerable devices. Remote code execution (RCE) was confirmed on two models, but other devices in the series may also be vulnerable.
The Nooie Cam app has between 50,000 and 100,000 downloads on Google Play, indicating widespread use of the device. Bitdefender identified four different vulnerabilities. One of them, CVE-2020-15744, is related to stack overflow or memory corruption and could allow remote code execution.
Another vulnerability allows an attacker to access the camera’s RTSPS (audio/video) streams. Nooie uses the MQTT protocol to transmit the status of IoT devices and obtain a URL for each stream. Research has shown that the MQTT server does not require authentication, allowing an attacker to subscribe to the stream and obtain the identifiers of all devices as they connect.
Nooie cameras use Amazon Web Services (AWS) to store recordings in the cloud. Each device has its own set of credentials, but a potential attacker can access them by forging a request on behalf of the camera using the identifiers obtained from the MQTT server (uuid and uid). After that, the attacker gains access to the stored video recordings.
In November 2020, Bitdefender privately disclosed several vulnerabilities and provided proof of concept with a request for patches. After no response from the manufacturer, the company publicly disclosed the vulnerabilities and offered recommendations to mitigate the risks. At the time of publication, Nooie had not responded to Bitdefender’s requests and had not provided assistance to users of the affected cameras.