Skip to main content
  1. Home
  2. Smart Home
  3. News

Mi-Cam baby monitors are easily hackable, so you may want to turn yours off

Add as a preferred source on Google
Hijacking of arbitrary miSafes Mi-Cam video baby monitors

You may depend upon your baby monitor to keep an eye on your precious little one, but a newly discovered vulnerability suggests that parents may not be the only ones watching their children. As per a warning from Austrian cybersecurity company SEC Consult, it would appear that the Mi-Cam baby monitor is susceptible to “multiple critical vulnerabilities which include unauthenticated access and hijacking of arbitrary video baby monitors.”

Recommended Videos

Around 50,000 folks are estimated to have Mi-Cams in their homes, and it would seem that any of them could fall prey to hackers. Ill-intentioned actors can allegedly hack into Mi-Cams and use them to spy on just about anything the cameras can see.

SEC Consult claims that it has tried to contact MiSafe, the company behind the Mi-Cam, to warn it against the potential vulnerabilities. Unfortunately, the security firm says that it has received no answer, and consequently, is urging customers to turn off the Mi-Cams in order to protect themselves.

In order to hack into the Mi-Cam, an attacker would simply need to set up a proxy server capable of intercepting and modifying an HTTP request between a smartphone and device. In this way, attackers would be able to check out Mi-Cam footage without ever entering a password on the device’s companion app. Moreover, SEC Consult claims that there are several APIs that helped them attain information on how to connect to the Mi-Cam cloud network and actually toy with the baby monitor.

As Johannes Greil, head of the SEC Consult Vulnerability Lab noted, “Information retrieved by this feature is sufficient to view and interact with all connected video baby monitors for the supplied [user ID].” Apparently, user IDs were also quite easy to guess.

In SEC Consult’s white-hat hacking efforts, they were able to completely automate the interception of content between the Mi-Cam and its cloud server, which made it easy to effectively set up a standing live-stream of video feeds.

Getting these (among other) issues resolved has proven to be a challenge, especially as it is not entirely clear as to who is responsible for Mi-Cams. While MiSafe is the actual creator of the device, QiWo Smartlink Technology seems to have the rights to the technology. Forbes reports that QiWo is indeed responsible for software updates, and that the company will be reaching out to the Securities Exchange Commission (SEC) in order to address security issues as soon as possible.

Luckily, it would appear that Mi-Cams are no longer in production, which means that you can no longer buy these faulty baby monitors. But if you’re one of the 50,000 or so individuals who already have one of these cameras, you’ll likely want to turn them off for the time being.

Lulu Chang
Fascinated by the effects of technology on human interaction, Lulu believes that if her parents can use your new app…
Beatbot AquaSense X review: The pool cleaner for those that want to be pampered
It's a nothing short of a self-cleaning nirvana for your pool. But as they say, nothing fine comes without a fittingly handsome fee.
Beatbot Aquasense X robot, AstroRinse station and iSkim

view at amazon

Quick take: 

Read more
An unpatched Shark vacuum flaw could put your smart home at risk
The vulnerability affects SharkNinja robot vacuums and stems from a misconfigured cloud security policy rather than a firmware bug.
Shark RV2320S Matrix Self-Emptying Robot Vacuum Featured

Robot vacuums are supposed to clean the house. Turns out this one was mapping it for strangers. Security researchers have disclosed a critical vulnerability affecting SharkNinja's cloud-connected robot vacuums that could allow attackers to remotely access sensitive information, including live camera feeds, home maps, Wi-Fi passwords, and even execute commands on affected devices. More concerningly, the issue reportedly remains unpatched despite being responsibly disclosed to SharkNinja months ago.

How can a vacuum become a spy?

Read more
Google Home Speaker (2026) review: Smarter and punchier, with a subscription pinch
Google's latest smart speaker pairs Gemini with better sound and deeper smart home integration. What's not to love without spending over a $100?
Sphere, Body Part, Finger

View at Amazon

Quick Recap

Read more