Cyber Resilience Act

You know what tested safety means. From September 11, 2026 it applies to the connection too.

The Cyber Resilience Act requires manufacturers of connected products to provide the same demonstrable proof of security that tested product safety has always meant. Including for transport technology supplied by a third party.

The Data

What we did

We analyzed the Android companion apps of 240 camera and IoT products from 88 brands across Europe, using only publicly available sources. For each product we determine directly from the binary which P2P transport technology is embedded and which region it originates from.

240
apps analyzed
88
brands
38
EU manufacturers with a detected stack
26
depending on technology of Chinese origin

Platform Facts

The PPPP protocol family

Many connected baby monitors and IP cameras use the CS2 Network P2P protocol family, commonly known as PPPP. At the platform level, the documented record includes:

CVE-2020-9525

(CVSS 8.1, high): an authentication flaw in CS2 Network P2P through 3.x that enables a man-in-the-middle attack on video and audio streams and the capture of credentials. Source: NVD.

CVE-2020-9526

(CVSS 5.9, medium): session data exposed to the network's supernodes. Source: NVD.

Paul Marrapese

DEF CON 28 (2020), "Abusing P2P to Hack 3 Million Cameras": predictable device IDs allowed connections to more than 3.6 million iLnkP2P devices; CS2 Network P2P is used in more than 50 million devices; plus a pre-auth weakness from firmware analysis.

Wladimir Palant (2025)

The CS2 family's "encryption" is better described as obfuscation. PPPP "isn't really peer-to-peer as advertised" but relies on central servers, though bulk data can flow over a direct connection between client and device. Authentication signatures can be bypassed via older unsigned message types.

Characteristic of the family: proprietary obfuscation rather than documented cryptography, no published protocol and central rendezvous servers. The transport is typically designed by a Chinese vendor and operated by that vendor's licensee.

These are facts about the protocol family. We make no claim about individual devices of any particular brand.

From September 11, 2026

Manufacturer responsibility

Under the Cyber Resilience Act the manufacturer is responsible for the firmware and transport of its products even when these come from a supplier.

For a transport with no European support, this raises a practical question: who fixes a vulnerability, and on what timeline?

What the CRA requires

  • Reporting obligations for actively exploited vulnerabilities (from September 11, 2026)
  • A vulnerability-handling process
  • Coordinated disclosure

Why Nabto

A European, documented alternative

Nabto is a Danish P2P vendor with a published security architecture: DTLS with elliptic-curve cryptography, a public-key trust model in which the basestation cannot decrypt peer traffic, and documented protocols rather than obscurity.

Nabto and the CRA Technical documentation

Torsten Born Steinel

The seamless integration, great support and high security of the technology matched our high standards and made Nabto the perfect choice for remote access to our sensor light cameras

Torsten Born

Head of R&D, STEINEL

Questions about the analysis or the technology?

Talk to us about the method, the findings or the technical architecture.

Get in touch