Security Advisory – Foscam App MQTT Authorization Vulnerability
Foscam is committed to protecting the privacy and security of our users and products. We recently addressed a security vulnerability affecting the MQTT authentication and device-connectivity functionality used by the Foscam App for Android and iOS.
The vulnerability could have allowed an attacker with MQTT access available to a legitimate application instance to access device information associated with other Foscam users.
Foscam responded immediately after receiving the report. We deployed server-side mitigations to close the cross-account data-access path and strengthen authorization controls. These protections apply to all users regardless of their installed app version. Additional security hardening is included in Foscam App version 5.3.25.
Affected versions:
- Foscam App for Android and iOS, version 3.2.1 through versions prior to 5.3.25
Recommended user actions:
- Update the Foscam App to version 5.3.25 or later through the official app store.
- Keep your Foscam camera firmware up to date.
- As an additional precaution, use a strong, unique password for each camera.
We would like to thank independent security researcher Abbas Rajabpour for discovering and responsibly reporting this vulnerability. His professionalism and cooperation throughout the coordinated disclosure process helped Foscam investigate and remediate the issue promptly.
Foscam will continue to strengthen the security of our products and services. If you believe you have identified a security issue involving a Foscam product or service, please contact support@foscam.com.
CVE: Pending assignment
Effective date: September 21, 2026

