Camveil: Unveiling Security Camera Vulnerabilities Through Multi-Protocol Coordinated Fuzzing
Fuchen Ma, Yuqiao Yang, Yuanliang Chen, Yanyang Zhao, Ting Chen, Yu Jiang
Abstract
Security cameras are widely deployed in safetycritical environments, supporting real-time video streaming and device control via protocols such as RTSP, ONVIF, and HTTP. Vulnerabilities in these systems can lead to frozen video feeds or surveillance failures, potentially resulting in property or safety losses. While fuzzing is a useful technique for discovering vulnerabilities, existing protocol and IoT fuzzers typically treat each protocol independently, overlooking the cross-protocol dependencies present in real-world cameras. To address this gap, we propose CAMVEIL, a fuzzing framework designed to uncover vulnerabilities in security cameras through multi-protocol coordinated fuzzing. The key insight is that certain protocols can modify the internal state of the camera, indirectly affecting the behavior of other protocols, making some vulnerabilities only discoverable through state-dependent, cross-protocol interaction. To exercise such interactions, CAMVEIL builds a protocol-aware camera status model that abstracts internal camera states and defines their dependencies across protocols. Guided by this model, CAMVEIL generates coordinated test sequences to explore interleaved protocol behaviors. Additionally, it integrates a logic-aware monitoring component that continuously analyzes response packets to detect semantic inconsistencies or abnormal control flows. Using this approach, CAMVEIL has discovered 22 previously unknown vulnerabilities across 9 industrial camera models from Hikvision, Honeywell, TP-Link, FOSCAM, EZVIZ, and Santachi. These flaws could allow attackers to disrupt live video streams or disable camera functionality, potentially causing critical surveillance failures.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- CMFuzz: Parallel Fuzzing of IoT Protocols by Configuration Model Identification and SchedulingQi Xu, Fuchen Ma, Yuanliang Chen, Wanli Chen et al.DAC 2025 · 1 citation
- PAVFuzz: State-Sensitive Fuzz Testing of Protocols in Autonomous VehiclesFeilong Zuo, Zhengxiong Luo, Junze Yu, Zhe Liu et al.DAC 2021 · 30 citations
- SPFuzz: Stateful Path based Parallel Fuzzing for Protocols in Autonomous VehiclesJunze Yu, Zhengxiong Luo, Fangshangyuan Xia, Yanyang Zhao et al.DAC 2024 · 11 citations
- SemFuzz: A Semantics-Aware Fuzzing Framework for Network Protocol ImplementationsYanbang Sun, Quan Luo, Yuelin Wang, Qian Chen et al.WWW 2026
- DRVFuzz: Data-Sensitive RISC-V CPU FuzzingZehong Yu, Yuanliang Chen, Zhen Yan, Xudong Zhang et al.USENIX Security 2026
