
V3 firmware updates this last year have been flaky at best. This forced firmware update may have similar issues. Cameras should be power cycled or at least restarted before pushing firmware in my opinion.
I’m sure they’ll offer you a $10 gift card…
![]()
So… a couple questions:
-
Once this update is applied, is the camera secure from future attacks?
-
If the camera was compromised prior to firmware update and fix, does applying the latest firmware remove previous “owning” of device of security vulnerability OR is compromised access
removed? -
Local network access. This could be provided by an app on a local network device (eg smartphone using Wyze app and security flaw in Wyze app). Or a compromised device on network (Wyze cam hacked from cloud/service). Or compromised network.
What exactly was the vulnerability (attack surface, attack window, attack behaviour, remediation, etc)?, 3rd party software library used in Wyze firmware? How long has this issue been accessible and provided a window of opportunity to hack the cameras and gain local camera and/or possibly compromise camera and launch attacks? Was vulnerability remote access to camera functions only, or visibility and ability to use camera to attack other devices inside the local network? Printer temporary memory was used years ago as way to attack other local network devices. Given device was compromised, what else could have happened and how does user remediate?
I get vendors like Wyze not disclosing vulnerabilities fully to protect users (and themselves from liability, reputational damage, etc) but lack of information or misinformation can be just as damaging, as user expected to manage, own and control… without ALL the information. BEST PRACTICES with security of camera
Is not present in installation instructions… and is not proactive w AI support either (maybe in future).
Bottom line… lots of opportunities for growth here in security (why software testing didn’t reveal, will it next time?), communications, firmware update process, best practices, education, etc
The cam is safe from this vulnerability.
No cam is safe from future attacks. So long as there are knucklehead hackers out there with the time and desire to create a new tool to punch a new hole in the firmware, there will always be a need for new security updates. We can only hope that the hackers who are working that hard at breaking firmware are on the good guy’s side and are doing it for the Bounty money from Wyze when they submit it to Wyze.
All of that is covered in great detail within the News Articles that reported it and published online by the spiteful hacker who uncovered the RCE vulnerability.
I had the same issue with 3 of 5 cameras being offline. Are you still having problems or did the issue got resolved?
Well said and totally agree! Block all open ports not used or needed in your router. Create an approved list of MAC addresses and block all others from even connecting.
People should worry about the other slew of apps for various other products because those apps used to control lights or whatever have most likely saved your network credentials. As Slab, Carver, and others have said, IoT things should always be separated and isolated from your main network.
Great job guys for the non complicated explanations so others not as savvy can understand. I would like to advise as well to use WPA3 if your routers support it for your main devices (desktop, laptop, etc). IoT things, from what i have anyways, only support WPA2. Just a suggestion.
Continuing the discussion from Update Your Wyze Cam v3 Firmware For Latest Security Updates 10/30/23:
Since the firmware upgrade last week, all three of my Cam v3 were off line, I deleted one cam and did the following
- a factory reset,
- created a IoT specifically for 2.5Ghz network, and
- added that cam as a new device. However, I kept getting “unable to find specific network name”.
I happen to have an extra brand new Cam v3 and did the above - added a new cam, added to the IoT network on 2.5 Ghz and added that cam as a new device. And it worked. As I finished the set-up, I was asked if I want to do a firmware update. I canceled to avoid repeating the problem encountered by all my other Cam v3. Whatever that firmware did, it certainly is a suspected root cause
Make sure the newly created IoT network is not hidden. Reboot the router, connect your phone to the IoT network, then try connecting the camera. It should first attempt to pull the SSID from phone if not, manually enter it. Let me know. I’m curious to see if it addresses your issue. Good luck.
what is the procedure to update wyze cam v3 firmware
List of latest firmware: https://support.wyze.com/hc/en-us/articles/360024852172
How to check your Cam v3 version and update: https://support.wyze.com/hc/en-us/articles/360031490651
I rolled my cameras back due to issues with the firmware that I suspected after the second camera applied the patch and then started having connectivity issues in a way that only 2 bars were seen on the camera’s wifi signal strength. It was not able to send HD video and the transfer rate would drop to 0.0 KB/s and stay there for a bit. It suffered severe video lag and was useless. Rolling back took 2 or 3 factory resets to get the cameral to operate successfully again. That is why I thought the first cameral was bad. I did the factory reset as instructed when going back and it still had the same behavior as before rolling back following the upgrade. I was working with support to return the first camera when a second one started doing the same thing. I would have already sent the first one back but they were not moving fast and having trouble with the return policy given the changes around the holidays. Then I noticed the firmware had been updated to the latest on the second camera and became confident that the firmware had done something strange. I rolled them all back to the firmware they were on when they arrived and reset them 3 times (long hold) and they are all operating correctly. Hope they figure out the issues. Hope this helps if anyone is having similar issues.
What cameras do you have and what firmware version did you roll back to?
I have V3 cameras. I had one previously and bought three more during Black Friday deals. The new ones came with 4.36.9.139 loaded. So I rolled them all back to that version. My older one had been offline for a few months while we worked on the house. So I am not sure what version it was on. I think it might have been 4.36.10.4054, likely a later version than the new cameras had. I will start testing newer firmware, but likely stay away from the current version until they release a new version that corrects the current issues (reportedly). Then try on one and compare. I was trying the unlimited service on a deal to see if I like it. The streaming feature was nice and if I had not been playing with that I might not have noticed right away. Hope that helps. Like I said, if you do roll back, I had to hard reset two or three times to get the camera stable and working correctly. Once was not enough. Also, it is important to note that the camera appeared to be working correctly except for the glitches with the wifi transmission. It did connect, and it did send information. Just not at the same or acceptable level.
where can i find disclosure on those “security improvements” after this one? What exploits did you fix? Because everything after v4.36.9.139 from 2022-05-18 is broken, greyed out the Playback button from the Events page and the only way to get it back is to downgrade to v4.36.9.139.
You can’t.
Even if it is due to an exploit (which it might not be). Most companies rarely post this, particularly not before most users have applied the update, or it would make hackers more likely to exploit it. Having said that, not all security updates/improvements are fixing exploits. Sometimes it is just changing protocols, or any number of other things. Just as an easy to understand example, lets say a company updated their encryption algorithm from where it would’ve taken a brute force attempt 1,000 years to brute force their way into it (already secure), to one that would take 1,000,000 years to do and also improves the efficiency so things are faster and less strenuous on the server. It’s still a “security improvement” but isn’t necessarily due to any “exploit” or vulnerability.
Regardless, Wyze (and many other companies that are not open-source) rarely mention what exactly they changed. It adds an extra level of security to not disclose it unless there is already a public CVE.
Well said. ![]()