Vulnerability
Published 2026-09-16
Verified 2026-09-19

Flock ALPR cameras: aged Android/Linux build plus hard-coded API key to mint device credentials

Micah Lee (16 September 2026; dataset from DDoSecrets / stegan0gram field extraction, also covered by 404 Media and Wired) analyses firmware from an in-use Flock Safety automatic licence-plate reader (ALPR) camera. The unit ran a modified Android 8.1 build dated 5 June 2025 on Linux 3.18.71 — far past vendor/Google support — and ships multiple Flock apps. Lee documents a hard-coded x-api-key in an app used to request device credentials from hpnotiq.flocksafety.com (MAC-address keyed), with returned credentials stored in plaintext and usable to mint bearer tokens via device-login.flocksafety.com. Lee lists older public Android/kernel CVEs the patch level likely predates but does not claim live exploitation tests on this hardware. Flock gave a statement to 404 Media/Wired (per Lee). No CVE assigned in the write-up. Primary: Micah Lee analysis; context: DDoSecrets dataset.

Product
Flock Safety ALPR / surveillance cameras (Android-based firmware)
Versions
Analysed image: Android 8.1 build 2025-06-05; Linux 3.18.71 (one field unit)
Exploited in Australia?
unknown
Patch to
Operators of Flock (or similar) ALPR estates: demand current supported OS/firmware, rotate any exposed device API keys/credentials, restrict camera management planes; do not reuse leaked keys from public research

Primary: Micah Lee — Flock cameras hard-coded credentials (16 Sep 2026) · 404 Media — Flock camera software / ALPR dataset context (with Wired)

tech ot ics network