← IoT Privacy Database

Furbo Dog Camera

Tomofun · Camera / Doorbell

✓ Reviewed

3.0Surveillance
Index
Policy — what its policy permitsC
Evidence — what research provesB

Always-on, cloud-connected treat-tossing pet camera with two-way audio and a Dog Nanny event-recording subscription. Captures audio/video of anyone in frame plus app geolocation; its privacy policy permits using customer 'Content' to refine AI algorithms and disclosing personal information to third-party marketers, and treats de-identified/aggregated data as outside personal-information protections, though it states it does not currently sell personal information. Heavily studied by independent security researchers who repeatedly found serious flaws over several years: firmware root RCE (Somerset Recon, 2021-22), an unauthenticated cloud photo API and zero-click account takeover (Lethal Bit, 2018), and a 2025 disclosure of ~17 CVEs including a hard-coded root password with no vendor response.

Why this rating

POLICY 63 = 100 -15 sensitive-collection (always-on audio/video incl. bystanders + app geolocation; confirmed by Mozilla and the vendor policy) -15 broker-disclosure (privacy policy Sec. 4(e): 'Tomofun may disclose your personal information to third parties for marketing purposes') -7 policy-vagueness (policy Sec. 3(h): customer 'Content data' used to 'test and refine our artificial intelligence algorithms'; policy Sec. 1 defines aggregated/anonymized data as outside 'personal information', so de-identified data can be shared without those protections). No sells-data deduction: policy Sec. 12 states 'We do not currently sell your Personal Information.' No confirmed indefinite-retention (Dog Nanny cloud recording is event-based/24h). All POLICY deductions verified against the primary Tomofun/Furbo privacy policy, so not reliant on secondary readings. POLICY 63 = grade C. EVIDENCE 75 = 100 -10 security-negligence (Somerset Recon 2021-22 firmware root RCE: CVE-2020-24918 RTSP-header buffer overflow [Part I] + CVE-2021-32452 ldc.cgi webserver command injection reachable via a digest-auth realm-spoof [Part II]) -5 security-negligence (Lethal Bit / Dolev Farhi 2018, counted at half weight as >5 years old: unauthenticated Daily Events API exposing other users' photos via a guessable Chicony MAC prefix + unauthenticated treat-toss audio upload + zero-click account takeover) -10 security-negligence (2025 disclosure of ~17 CVEs incl. hard-coded root password CVE-2025-11649 on Furbo 360/Mini, vendor non-response). No confirmed data sale, breach, regulatory action, or law-enforcement pipeline (Mozilla notes no known major breach at review time). Device is well-studied (Mozilla + two independent security-research bodies + a 2025 CVE cluster), so the unstudied rule does not apply. EVIDENCE 75 = grade B. Confidence high: all material claims verified against primary sources.

What it is

Manufacturer
Tomofun
Category
Camera / Doorbell
Model years
2016-present
Market status
Current
Companion app
Furbo - smartest pet camera (iOS/Android)

The evidence 5

Independent research, regulatory action, lawsuits, breaches and journalism about this device — the "what actually happens" axis. Each links to its source.

  1. Security research · Somerset Recon · 2021

    Multi-part independent research on the Furbo dog camera. Part I (this URL) achieves root code execution via CVE-2020-24918, a buffer overflow in the RTSP authentication-header parser (unbounded sscanf into a 132-byte buffer); Part II adds a more reliable root exploit via CVE-2021-32452, a command injection in the ldc.cgi webserver of the Furbo 2.5T reachable after spoofing the digest-auth realm to ycam.com.

    Why it matters here: Supports EVIDENCE security-negligence (firmware root RCE) and the works_offline=0 / cloud-exposure profile.

  2. Security research · Lethal Bit (Dolev Farhi) · 2018

    Independent research (2018, updated 2021) documenting three cloud-side flaws: an unauthenticated Daily Events API returning other users' photos categorized Person/Dog Selfie/Dog Activity, protected only by a guessable Chicony (B0:C0:90) MAC prefix in the URL with no device-to-account association; an unauthenticated treat-tossing audio-upload API; and a zero-click account takeover via a password-reset token returned in the API response.

    Why it matters here: Independent second research body; supports EVIDENCE security-negligence (counted at half weight as >5 years old) and the always-cloud / works_offline=0 profile. Actual source of the 'unauthenticated photo API' claim (previously misattributed to Somerset Recon).

  3. Cve · NIST NVD · 2025-10-12

    Hard-coded password in the Root Account Handler on Furbo 360 (<=FB0035_FW_036) and Furbo Mini (<=MC0020_FW_074); CVSS ~6.3 (NIST) to 7.0 (VulDB). One of ~17 Furbo 360/Mini CVEs (CVE-2025-11634..11649 range) from a 2025 hardware-hacking disclosure. NVD/VulDB note the vendor was contacted but did not respond.

    Why it matters here: Supports EVIDENCE security-negligence (recent, distinct research effort; vendor non-response).

  4. Privacy analysis · Mozilla Foundation · 2021-11-08

    Independent policy review confirming Furbo collects audio/video of anyone in frame plus geolocation, uses captured video to test/refine AI algorithms, and may disclose personal information to third parties for marketing, while noting Tomofun does not currently sell personal information and had no known major security breach at the time of review.

    Why it matters here: Corroborates POLICY sensitive-collection, broker-disclosure and policy-vagueness deductions and the no-sale finding.

  5. Policy · Tomofun / Furbo · accessed 2

    Primary vendor policy. Verbatim: 'We do not currently sell your Personal Information' (Sec. 12); 'Tomofun may disclose your personal information to third parties for marketing purposes' (Sec. 4(e)); when Smart Dog Alerts is enabled 'we use your Content data to test and refine our artificial intelligence algorithms' (Sec. 3(h)); and 'Aggregated or anonymized information does not constitute personal information' (Sec. 1), i.e. de-identified data falls outside the policy's personal-information protections.

    Why it matters here: Primary-source basis for the POLICY sensitive-collection, broker-disclosure and policy-vagueness deductions and the no-sale finding; removes reliance on secondary readings.

Descriptive, cited, not legal advice; ratings are versioned and corrections create a new version. Data from the IoT Info Grabber DB research project, CC BY-SA 4.0.

← Back to the IoT Privacy Database