CVE-2018-16225: Qbeecam Qbee Multi-Sensor Camera Firmware

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

The QBee MultiSensor Camera through 4.16.4 accepts unencrypted network traffic from clients (such as the QBee Cam application through 1.0.5 for Android and the Swisscom Home application up to 10.7.2 for Android), which results in an attacker being able to reuse cookies to bypass authentication and disable the camera.

Affected products

  • Qbeecam Qbee Multi-Sensor Camera Firmware: up to and including 4.16.4
  • Qbeecam Qbeecam: up to and including 1.0.5
  • Swisscom Swisscom Home App: up to and including 10.7.2

Published 2018-09-18. Last modified 2026-06-17.