The seamless integration, great support and high security of the technology matched our high standards and made Nabto the perfect choice for remote access to our sensor light cameras
Cyber Resilience Act
You know what tested safety means. From September 11, 2026 it applies to the connection too.
The Cyber Resilience Act requires manufacturers of connected products to provide the same demonstrable proof of security that tested product safety has always meant. Including for transport technology supplied by a third party.
The Data
What we did
We analyzed the Android companion apps of 240 camera and IoT products from 88 brands across Europe, using only publicly available sources. For each product we determine directly from the binary which P2P transport technology is embedded and which region it originates from.
Platform Facts
The PPPP protocol family
Many connected baby monitors and IP cameras use the CS2 Network P2P protocol family, commonly known as PPPP. At the platform level, the documented record includes:
(CVSS 8.1, high): an authentication flaw in CS2 Network P2P through 3.x that enables a man-in-the-middle attack on video and audio streams and the capture of credentials. Source: NVD.
(CVSS 5.9, medium): session data exposed to the network's supernodes. Source: NVD.
Paul Marrapese
DEF CON 28 (2020), "Abusing P2P to Hack 3 Million Cameras": predictable device IDs allowed connections to more than 3.6 million iLnkP2P devices; CS2 Network P2P is used in more than 50 million devices; plus a pre-auth weakness from firmware analysis.
The CS2 family's "encryption" is better described as obfuscation. PPPP "isn't really peer-to-peer as advertised" but relies on central servers, though bulk data can flow over a direct connection between client and device. Authentication signatures can be bypassed via older unsigned message types.
Characteristic of the family: proprietary obfuscation rather than documented cryptography, no published protocol and central rendezvous servers. The transport is typically designed by a Chinese vendor and operated by that vendor's licensee.
These are facts about the protocol family. We make no claim about individual devices of any particular brand.
From September 11, 2026
Manufacturer responsibility
Under the Cyber Resilience Act the manufacturer is responsible for the firmware and transport of its products even when these come from a supplier.
For a transport with no European support, this raises a practical question: who fixes a vulnerability, and on what timeline?
What the CRA requires
- Reporting obligations for actively exploited vulnerabilities (from September 11, 2026)
- A vulnerability-handling process
- Coordinated disclosure
Why Nabto
A European, documented alternative
Nabto is a Danish P2P vendor with a published security architecture: DTLS with elliptic-curve cryptography, a public-key trust model in which the basestation cannot decrypt peer traffic, and documented protocols rather than obscurity.
Questions about the analysis or the technology?
Talk to us about the method, the findings or the technical architecture.

