CameraRisk

Coverage and gaps

Generated from the current build — 5 September 2026

What this dataset contains, and more usefully what it does not. Every figure below is counted from the build rather than asserted, so it changes when the data does.

What is held

Vendors tracked74
Vendors with at least one CVE69
Products with at least one CVE3293
Vulnerabilities1279
In CISA KEV22

Gaps in the vulnerability records

CVEs with no CVSS score in NVD0
CVEs with no EPSS score0
Products whose device type could not be derived2853
Products with no affected version recorded1021
Products with exactly one CVE1262

Products in the last two rows carry thin pages. They are built so that links resolve, but most are excluded from search-engine indexing by the site's own quality threshold — a row in a database is not a reason to publish a page.

Vendors tracked with no CVEs found

These vendors are in scope and were queried. NVD returned no CVE naming their products in the CPE data. Read this carefully: for cloud-first vendors in particular, the absence reflects non-participation in the CVE system rather than an absence of vulnerabilities. A vendor that assigns no CVE identifiers produces an empty record here whatever its security history, so this list should be read as a statement about CVE participation and nothing else.

eufy / Anker · Western Digital · Ubiquiti · Xiaomi · DoorBird

Products excluded by the video filter

Vendors who also make routers, storage or building controls have their namespace filtered to video products only. These are the products that filter removed. If a camera or recorder is listed here, the filter is wrong and we would like to hear about it.

VendorExcludedSample of excluded products
Schneider Electric 1760 140_cpu6x, 140_cpu6x_firmware, 140_noc_77101, 140_noc_77101_firmware, 140_noc_78x00, 140_noc_78x00_firmware, 140_noe_771x1, 140_noe_771x1_firmware
NETGEAR 1104 6r7500, 6r7500_firmware, ac1200_r6220, ac1200_r6220_firmware, ac1450, ac1450_firmware, ac2100, ac2100_firmware
TP-Link 1030 8840t, ac1750, ac1750_firmware, aginet, archer-c3150, archer-c3150_firmware, archer_a10, archer_a10_firmware
D-Link 847 6600-ap, 6600-ap_firmware, central_wifimanager, covr-2600r, covr-2600r_firmware, covr-3902, covr-3902_firmware, covr-x1870
Honeywell 369 ademco_atnbaseloader100_module, alerton_ascent_control_module, alerton_ascent_control_module_firmware, alerton_bcm-web, alerton_bcm-web_firmware, alerton_compass, alterton_visual_logic, alterton_visual_logic_firmware
Tenda 204 11n, 11n_firmware, 4g03_pro, 4g03_pro_firmware, 4g06, 4g06_firmware, 4g300, 4g300_firmware
QNAP 132 ai_core, authenticator, container_station, download_station, ej1600, ej1600_firmware, file_station, helpdesk
Bosch 124 access, access_easy_controller, access_easy_controller_firmware, access_management_system, access_professional_edition, amc2, amc2_firmware, b420
TRENDnet 110 teg-30102ws, teg-30102ws_firmware, teg-40128, teg-40128_firmware, tew-410apb, tew-410apb_firmware, tew-411brpplus, tew-411brpplus_firmware
Johnson Controls 104 ac2000, ac2000_firmware, application_and_data_server, bcpro, c-cure_9000, c-cure_9000_firmware, c-cure_web, cevas
Synology 96 active_backup_for_business, active_backup_for_business_agent, active_backup_for_business_recovery_media_creator, active_backup_for_microsoft_365, activeprotect_agent, antivirus_essential, application_service, assistant
Realtek 68 adsl_router_soc_firmware, audio_driver_firmware, bluetooth_mesh_software_development_kit, ecos_msdk, ecos_msdk_firmware, ecos_rsdk, ecos_rsdk_firmware, hd_audio_codec_drivers
Panasonic 52 aiseg2, aiseg2_firmware, arbitrator_back-end_server_mk_2.0_vpu, arbitrator_back-end_server_mk_2.0_vpu_firmware, arbitrator_back-end_server_mk_3.0_vpu, arbitrator_back-end_server_mk_3.0_vpu_firmware, bb_hcm511, bb_hcm515
Edimax 37 6114wg, 6114wg_router_firmware, 7237rpd, 7237rpd_firmware, br-6104k, br-6104k_router_firmware, br-6208ac, br-6208ac_firmware
Western Digital 26 ibi, my_cloud, my_cloud_dl2100, my_cloud_dl4100, my_cloud_dl4100_firmware, my_cloud_ex2, my_cloud_ex2100, my_cloud_ex2100_firmware
Aqara 11 board_service, cloud_developer_portal, cloud_oauth_authorization_endpoint, cloud_production_api, developer_portal, home, hub_m2, hub_m2_firmware
Ubiquiti 7 airos_4_xs2, airos_4_xs5, edgeos, edgeswitch, edgeswitch_firmware, edgeswitch_xp_firmware, ucrm
eufy / Anker 6 eufy_homebase_2, eufy_homebase_2_firmware, homebase_2, homebase_2_firmware, nebula_capsule_projector, nebula_capsule_projector_firmware
Xiaomi 2 fileexplorer, mitalk_messenger

Fetch errors in this build

None. Every vendor namespace in scope returned a complete result set.

Known structural limits

Four, none of which we can fix from public data.

Vendors who do not assign CVEs are invisible here. A vendor that fixes issues in a firmware release without publishing an identifier produces no record anywhere, and no amount of care in this pipeline will surface it.

Component vulnerabilities are not attributed to devices. Where a camera embeds a vulnerable library, the CVE names the library. Unless the device vendor publishes its own advisory, nothing connects the two. This site tracks several such components as vendors in their own right, which is the closest approximation available.

CPE data is incomplete and inconsistent. Some CVE records name a vendor without enumerating models. Those CVEs appear against fewer products than they actually affect.

There is no lifecycle data. End-of-support is frequently the most decisive fact about a device's risk, and no public machine-readable source for it exists across these vendors.

Counts generated at build time from data/build/dataset.json. Method: methodology.