Skip to main content

Mi-Cam baby monitors are easily hackable, so you may want to turn yours off

Hijacking of arbitrary miSafes Mi-Cam video baby monitors

You may depend upon your baby monitor to keep an eye on your precious little one, but a newly discovered vulnerability suggests that parents may not be the only ones watching their children. As per a warning from Austrian cybersecurity company SEC Consult, it would appear that the Mi-Cam baby monitor is susceptible to “multiple critical vulnerabilities which include unauthenticated access and hijacking of arbitrary video baby monitors.”

Around 50,000 folks are estimated to have Mi-Cams in their homes, and it would seem that any of them could fall prey to hackers. Ill-intentioned actors can allegedly hack into Mi-Cams and use them to spy on just about anything the cameras can see.

SEC Consult claims that it has tried to contact MiSafe, the company behind the Mi-Cam, to warn it against the potential vulnerabilities. Unfortunately, the security firm says that it has received no answer, and consequently, is urging customers to turn off the Mi-Cams in order to protect themselves.

In order to hack into the Mi-Cam, an attacker would simply need to set up a proxy server capable of intercepting and modifying an HTTP request between a smartphone and device. In this way, attackers would be able to check out Mi-Cam footage without ever entering a password on the device’s companion app. Moreover, SEC Consult claims that there are several APIs that helped them attain information on how to connect to the Mi-Cam cloud network and actually toy with the baby monitor.

As Johannes Greil, head of the SEC Consult Vulnerability Lab noted, “Information retrieved by this feature is sufficient to view and interact with all connected video baby monitors for the supplied [user ID].” Apparently, user IDs were also quite easy to guess.

In SEC Consult’s white-hat hacking efforts, they were able to completely automate the interception of content between the Mi-Cam and its cloud server, which made it easy to effectively set up a standing live-stream of video feeds.

Getting these (among other) issues resolved has proven to be a challenge, especially as it is not entirely clear as to who is responsible for Mi-Cams. While MiSafe is the actual creator of the device, QiWo Smartlink Technology seems to have the rights to the technology. Forbes reports that QiWo is indeed responsible for software updates, and that the company will be reaching out to the Securities Exchange Commission (SEC) in order to address security issues as soon as possible.

Luckily, it would appear that Mi-Cams are no longer in production, which means that you can no longer buy these faulty baby monitors. But if you’re one of the 50,000 or so individuals who already have one of these cameras, you’ll likely want to turn them off for the time being.

Lulu Chang
Former Digital Trends Contributor
Fascinated by the effects of technology on human interaction, Lulu believes that if her parents can use your new app…
Nest Doorbell vs. Ring Battery Doorbell Plus: which is the better video doorbell?
The Ring Battery Doorbell Plus installed outside a front door.

Ring and Nest are responsible for some of the best video doorbells available. With easy-to-use smartphone apps, simple installation processes, and the ability to customize your motion alerts, the Ring Battery Doorbell Plus and Nest Doorbell have quickly established themselves as two of the best video doorbells money can buy.

But what exactly is the difference between these two popular gadgets? And which is better for your smart home?

Read more
The best Apple HomeKit devices for 2023
A person unlocking the Aqara U100 smart lock with their phone.

While not as widespread as Google Home or Amazon Alexa, Apple HomeKit remains one of the most popular smart home ecosystems of 2023. The software plays well with iOS devices, and several other gadgets such as smart lights, smart locks, thermostats, and cameras can be controlled using the fancy technology. If you’re looking to build your smart home around Apple’s ecosystem, here are the best HomeKit devices available today.
Locks

HomeKit doesn’t have the largest selection of smart locks, but that doesn’t really matter when you have something as well-rounded as the Aqara Smart Lock U100. Not only does it offer full HomeKit support, but you’ll even gain access to Apple home keys -- allowing you to unlock your door with your iPhone or Apple Watch. There’s also the standard keypad for entering a passcode, along with a fingerprint sensor that can store several dozen fingerprints (so your whole family can enter the home without worrying about forgetting their password or smartphone).

Read more
Secure your home with Ring Floodlight Cam Plus and save $80
Ring Floodlight Camera placed on a wall outside.

Best Buy has one of the best security camera deals at the moment with $80 off the Ring Floodlight Cam Plus Outdoor Wired Surveillance Camera. Usually priced at $200, it's down to $120 for a limited time only so if you're fast enough, you'll save a lot of cash. If you're looking to secure your home, keep reading while we tell you all about the advantages this security camera offers.

Why you should buy the Ring Floodlight Cam Plus
Considered to be one of the best floodlight cameras for someone seeking a hard-wired solution, the Ring Floodlight Cam Plus Outdoor Wired Surveillance Camera is a highly effective home security measure.

Read more