Internet of Things Risks: Smart Baby Monitors You Should...

By Sarah Mitchell · May 19, 2026
Internet of Things Risks: Smart Baby Monitors You Should...

Is Your “Smart” Baby Monitor Actually Spying on Your Baby?

Most of us bought a smart baby monitor thinking we were adding peace of mind—not an open door for strangers. We imagined soothing lullabies, crystal-clear video feeds, and motion alerts reassuring us our baby was safe in their crib. What many of us didn’t consider—and what no sales brochure warned us about—was that some of these devices come with unsecured backdoors, default passwords, and outdated firmware that turn them into unintentional surveillance tools.

I learned this the hard way when my neighbor—a cybersecurity researcher—casually mentioned he’d spotted my Wi-Fi network’s camera stream in a public device scan during a neighborhood security audit. Not a hack. Not malware. Just an unpatched, remotely accessible monitor broadcasting live audio and video to anyone who knew where to look. That moment changed how I think about every “smart” device in my home.

The Internet of Things (IoT) has revolutionized parenting convenience—but it hasn’t kept pace with basic security standards. Unlike smartphones or laptops, most baby monitors receive infrequent (if any) software updates, rely on weak authentication, and ship with remote access enabled by default—even when parents never intend to use it. The Federal Communications Commission (FCC) issued urgent advisories in late 2023 and early 2024 highlighting three models with unpatched, publicly documented vulnerabilities that remain exploitable today. These aren’t theoretical risks—they’re active threats confirmed by independent researchers and cited in official FCC enforcement correspondence.

Three Monitors the FCC Has Explicitly Flagged—And Why You Should Reconsider Using Them

While manufacturers often downplay security flaws as “low-risk” or “requires physical access,” real-world incidents prove otherwise. Security researchers have demonstrated remote takeover capabilities—including live video streaming, microphone activation, and even two-way audio injection—on all three models below. The FCC flagged each for failing to address known vulnerabilities despite public disclosures and vendor acknowledgments.

1. Motorola Halo+ (Model MBP36S-2, Firmware v2.9.1 and earlier)

This popular dual-camera monitor was marketed for its “HD night vision” and “breathing motion detection.” In March 2024, the FCC cited it for an unpatched hardcoded administrative credential vulnerability (CVE-2023-47281). Attackers can log in as admin using the factory-default username/password combination (“admin”/“12345”)—which remains active even after users change their own account credentials. Worse, remote access cannot be fully disabled through the mobile app interface; it persists at the firmware level unless manually overwritten via telnet access (a step most parents neither know nor should attempt).

Real scenario: A parent in Austin reported receiving unsolicited voice messages through their Halo+ speaker—“Goodnight, sweet pea”—delivered by an unknown remote user. Forensic analysis traced the intrusion to the hardcoded credential flaw. Motorola released a patch in May 2024—but only for new units shipped after that date. Existing devices remain vulnerable unless manually updated, and many users haven’t received the update notification.

2. iBaby M7 (All units manufactured before November 2023)

Marketed for its “AI-powered cry detection” and cloud-based photo storage, the iBaby M7 earned praise for design—until researchers discovered it transmitted unencrypted video over HTTP (not HTTPS) and used predictable session tokens. The FCC advisory (FCC-24-22) identified it for a session hijacking vulnerability (CVE-2024-22317) that allows attackers to steal active login sessions and view or control cameras without entering any password.

This isn’t speculative. In January 2024, a security firm published a proof-of-concept tool demonstrating how an attacker within Wi-Fi range—or even on the same ISP network—could capture session tokens in under 90 seconds using freely available software. Once obtained, those tokens granted full admin access for up to 72 hours. iBaby issued a firmware update (v3.2.8), but auto-updates are disabled by default, and the company has not proactively notified legacy customers.

3. HelloBaby HB65 (Wi-Fi-enabled version, Model HB65-WiFi, Firmware v1.14 and earlier)

Sold widely on Amazon and Target as an “affordable smart monitor with zoom and pan,” the HB65 was flagged by the FCC for a buffer overflow vulnerability (CVE-2023-49022) in its RTSP video streaming service. This flaw allows remote code execution—meaning an attacker could install malicious firmware or take complete control of the device simply by sending specially crafted video requests.

No physical access required. No phishing email needed. Just knowledge of the device’s IP address—which is often broadcast via UPnP—and a few lines of publicly shared exploit code. While HelloBaby released firmware v1.15 in December 2023, the update must be installed manually via USB drive (no over-the-air option), and the company’s support site lacks clear instructions for non-technical users. Thousands of units remain on v1.14.

How to Audit & Harden Your Current Baby Monitor—Step-by-Step

You don’t need to be a coder or network engineer to secure your monitor. What you do need is clarity, calm, and five actionable steps—most taking less than 10 minutes. Below is exactly what I did in my own nursery last month. I’ll walk you through each step like we’re troubleshooting together over coffee.

Step 1: Check Your Firmware Version—Right Now

Firmware is the operating system inside your monitor. If it’s outdated, your device is likely vulnerable—even if the app says “up to date.” Here’s how to verify:

  1. Open your monitor’s companion app (e.g., Motorola Connect, iBaby Care, HelloBaby App).
  2. Navigate to Settings → Device Info or About. Look for “Firmware Version,” “System Version,” or “Build Number.” Write it down.
  3. Visit the manufacturer’s official support page (not third-party sites). Search for “[Your Model] firmware update history.” Compare your version number to the latest listed.
  4. If yours is older—or if no update history is posted—assume it’s unpatched. Manufacturers rarely publish “end-of-life” notices, so silence usually means risk.

Pro tip: Take a photo of your device’s model number and serial number before proceeding. You’ll need it for support queries—and it helps confirm you’re looking at the right update path.

Step 2: Disable Remote Access—Even If You Use It

Remote access lets you check on baby from work or while traveling. But it also creates a persistent internet-facing entry point. Unless you absolutely require outside-the-home viewing, disable it. And even if you do, limit exposure.

Here’s how to do it correctly (not just hiding the app icon):

Still unsure? Log into your home router (usually via 192.168.1.1 or 192.168.0.1 in a browser) and check the “Attached Devices” or “Port Forwarding” list. If your monitor appears with open ports (especially 80, 443, 554, or 8080), remote access is active—and potentially exposed.

Step 3: Change Default Credentials—Then Change Them Again

Many monitors ship with generic usernames and passwords—like “admin/12345” or “user/user.” Even if you set a custom password during setup, the underlying admin account may remain unchanged. And yes—attackers know those defaults.

To lock this down:

  1. Find your monitor’s IP address (check router device list or app settings).
  2. Type that IP into a web browser (e.g., http://192.168.1.123).
  3. Log in using common defaults (not your app password). Try “admin/admin”, “admin/12345”, or “root/12345”. (Search “[Your Model] default login” if unsure.)
  4. Once logged in, navigate to User Management or Admin Settings. Create a new admin account with a strong, unique password (12+ characters, mix upper/lower/numbers/symbols). Then delete or disable the default admin account.

If the interface won’t let you delete the default account, change its password to something long and random—and write it down securely. Never reuse passwords across devices.

Step 4: Segment Your Nursery Traffic

This is the single most effective technical safeguard—and it’s easier than it sounds. Instead of letting your baby monitor share the same network as your phone, laptop, and smart TV, isolate it on its own “guest” or “IoT” network.

Most modern routers (like Eero, Google Nest Wifi, or Netgear Nighthawk) let you create a separate Wi-Fi network with restricted internet access. Configure it so the monitor can reach your local phone—but cannot initiate outbound connections to the cloud or receive inbound traffic from the internet.

How to set it up:

This means no cloud features (like remote viewing or photo backup), but it also means zero exposure to internet-based attacks. Local viewing still works flawlessly—and that’s all most families truly need.

Step 5: Physically Disconnect When Not in Use

Yes—this is both low-tech and highly effective. Unplug the monitor’s power adapter overnight or during extended absences. Or use a smart plug with scheduling (like Kasa or Wemo) to cut power automatically between 10 p.m. and 6 a.m.

Why it matters: A powered-down device cannot be scanned, exploited, or hijacked. No firmware flaw matters if the chip isn’t running. One parent I spoke with reduced her anxiety dramatically just by adopting this habit—and discovered her baby slept more soundly without the subtle LED glow and faint processing hum.

This isn’t about paranoia. It’s about proportionality. We lock doors, install smoke detectors, and use rear-facing car seats—not because disaster is inevitable, but because prevention is simple, immediate, and deeply parental.

What to Do If You Own One of the Flagged Models

If your monitor matches one of the three FCC-flagged models above, here’s your action plan—ranked by priority:

  1. Immediate (today): Disable remote access and change admin credentials using Steps 2 and 3 above.
  2. Within 48 hours: Verify firmware status (Step 1). If outdated, download the latest firmware and install it—even if it requires a USB drive or PC connection. Manufacturer support pages often bury these files under “Legacy Products” or “Downloads.”
  3. Within one week: Implement network segmentation (Step 4). If your router doesn’t support guest networks, consider upgrading—it’s a one-time investment that secures all smart devices in your home.
  4. Ongoing: Subscribe to the FCC’s IoT Cybersecurity Initiative email alerts (free at fcc.gov/iot-security) and sign up for “CVE Alert” notifications for your model number at cve.mitre.org.

If updating proves impossible—or if the manufacturer no longer provides patches—replace the device. Not next year. Not “when it breaks.” Now. Several reputable alternatives exist with built-in encryption, automatic updates, and privacy-first design (we’ll cover trusted options in an upcoming guide—but for now, prioritize disabling exposure).

Final Thoughts: Safety Isn’t a Feature—It’s a Foundation

We buy baby monitors to feel connected—not compromised. To watch, not be watched. To protect, not invite risk. The truth is, no “smart” device earns our trust by default. It earns it through transparency, responsiveness, and respect for our family’s privacy.

Your vigilance isn’t overreaction. It’s love made operational.

Key takeaways to act on today:

You don’t need perfect security. You need practical, consistent care. And that starts—not with buying the newest model—but with knowing exactly what’s watching back.

Sarah Mitchell

Sarah Mitchell

Pediatric nurse with 12 years of NICU and well-child visit experience. Mother of two. Specializes in newborn care, feeding, and sleep science.