VideoCybersecurity

A reference for securing video infrastructure

Video Cybersecurity

Security for IP cameras, NVRs, VMS platforms and connected video infrastructure.

A modern video-security estate is a fleet of networked computers running vendor firmware, speaking half a dozen protocols, reachable from the corporate network and often from the internet. It is usually bought by a physical-security team, installed by an integrator, and inherited by whoever runs the network. This site documents how to discover, assess, harden and monitor that estate.

The field

Cameras

Who is actually responsible for the camera on your ceiling, and how to find out

Vulnerability management

Why the standard scan-prioritise-patch pipeline degrades on a camera estate

CCTV estates

Analogue and hybrid estates, where the cameras are not network devices at all

Cloud video

Cloud-managed video, from full VSaaS to an on-premise camera phoning home

DVRs

The recorder at the coax end of the estate, and why it ended up on the internet

NVRs

Why the recorder, not the camera, is the highest-value asset in a video estate

ONVIF

What the interface standard specifies about authentication, discovery and TLS

Convergence

Who owns the cameras, who holds the passwords, and which rules actually oblige you

RTSP

A 1998 protocol with no transport security, running on almost every camera

VMS

Video management software is enterprise server software carrying unusual privilege

Research and guides

  • Camera firmware and the patching problem

    Camera firmware is versioned by silicon, delivered by hand and signed only above a floor — what that means for choosing a build and keeping an estate on it.

  • Where camera segmentation goes wrong

    Camera VLANs fail at the rule set more often than at the drawing. Vendor documentation shows the four places it happens, and what to write instead.

  • Common camera ports and protocols

    The ports cameras and VMS servers actually listen on, the shipped enabled-or-disabled state each vendor documents, and the numbers nobody has confirmed.

  • End-of-life cameras and cyber risk

    What an end-of-support commitment actually covers, whose clock it runs from, and which camera makers publish no lifecycle policy we could retrieve.

  • How cameras end up on the internet

    Every published count of internet-exposed cameras counts devices answering at a routable address, which is not the same population as the reachable one.

  • What Mirai did to the camera industry

    Cameras and DVRs are named in the Mirai charging documents. What three plea agreements admit, what researchers only estimated, and what nobody ever verified.

All research and guides · Atom feed

What this site is

Reference material compiled from primary sources: vendor documentation, the CVE Program's own records, regulatory text, and the NVD, CISA KEV and FIRST EPSS feeds. Every factual claim carries a source you can open. Where the evidence is thin — and for a lot of this subject it is — the page says so rather than filling the gap with confident prose. It does not claim operational experience it cannot evidence; what it claims is that the sources are real, cited and dated, which how we source sets out in full.

Current vulnerability intelligence for these products is maintained separately by VideoSOC; per-model vulnerability history lives on CameraRisk.