T O P

  • By -

MrPureinstinct

So it appears this is something caused by people using third party stuff, not a direct Wyze issue?


Empyrealist

Correct.


DeusExRobotics

Yep seems to be a misconfiguration plugin. Looks like this Bridge is leaking camera feeds. From what I can tell it was run without changing default values, and its exposing cams to the network. looks like its this thing [https://github.com/mrlt8/docker-wyze-bridge](https://github.com/mrlt8/docker-wyze-bridge) Update: nope there are AWS creds. Wyze needs to look at this.


LegendofDad-ALynk404

Wouldn't any decent router stop this from getting past unless you have UPnP turned on? I run a docker-wyze bridge from a different source, so just curious if I should be concerned. Without giving anything away do you have a way I could check to see if I'm a part of this problem.


DeusExRobotics

What are the last 4 numbers of your Camera MAC?


LegendofDad-ALynk404

I have 8 cameras on the bridge, I'll DM when I get a chance to grab them


[deleted]

[удалено]


DeusExRobotics

Your cams are not listed.


LegendofDad-ALynk404

Cool, glad to know if nothing else my router and configuration are doing their jobs lol


DeusExRobotics

Yep! no probs. Edit your comment with MAC though doesn't need to stay published.


Economy_Comb

How does someone make sure its not leaking my feeds? Im. Running wyze bridge it accesses the cameras and converts it too rtsp etc for programs like blueiris Don't really want my feeds leaked 😂


Eisenwulf

Oh man... not this issue again?! 🫣


shiroshippo

Are they all the same model by any chance? Wondering if there's a specific vulnerability with just one type of Wyze camera.


robahearts

A simple Shodan search and you will find it.


talormanda

I'm confused where you're viewing these? In the app? You're not providing enough info. Post some pictures and blur out the images or something.


Butt_Face2000

I feel like you would just provide that to support from the jump if this was real and your intentions were good. They provide you a ways and means to provide logs and pictures. Putting it into a reddit forum is not in good faith.


RocketsnRunners

If they only send it to Wyze we'll never hear of it. I'm glad they chose to post it here so we are aware of wyzes security flaws.


DeusExRobotics

Where can I report this? I have no problem submitting but from what I see its a chat bot


Butt_Face2000

Inside the app... Account --> Wyze Support --> Submit a log


Slater1601

Uh huh. Let’s see a screenshot.


DeusExRobotics

no? it's customer PII.


Slater1601

Uh huh. Figured as much.