In April 2019, security researcher Paul Marrapese reported two serious flaws in iLnkP2P, a peer-to-peer (P2P) system used by some internet-connected cameras and other devices. His scan identified more than 2 million vulnerable devices at the time. That is a historical estimate—not a count of devices vulnerable today.
The flaws, CVE-2019-11219 and CVE-2019-11220, could let attackers find exposed devices and interfere with connections to capture credentials. If you own a camera or other IoT device that may use iLnkP2P, identify its exact model and firmware, then check the manufacturer’s current support and security-update information before deciding whether to keep using it.
What is iLnkP2P?
iLnkP2P is a peer-to-peer system developed by Shenzhen Yunni Technology Company, Inc. It was designed to help people connect to IoT devices from a phone or computer. A coordinating P2P server helps establish the connection between the user and the device.
SecurityWeek reported on April 26, 2019, that iLnkP2P appeared in products sold under hundreds of brand names. The report listed Hichip, TENVIS, SV3C, VStarcam, Wanscam, NEO Coolcam, Sricam, Eye Sight and HVCAM, among others. Reported product types included cameras, baby monitors and smart doorbells. A brand name alone does not establish that a particular device uses iLnkP2P or is vulnerable.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
- 𝐄𝐚𝐬𝐲 𝐒𝐞𝐭𝐮𝐩 𝐈𝐧𝐝𝐨𝐨𝐫/𝐎𝐮𝐭𝐝𝐨𝐨𝐫 𝐂𝐚𝐦𝐞𝐫𝐚 — 2.5K HD video, vibrant color night vision and IP66, ensuring you never miss a moment, day or night,rainy or sunny. With dual-band 2.4G/5G WiFi & Plug and play setup of the cameras for home security - just download app and scan QR code! No tools needed for tabletop use, mounting screws included for walls
- 𝟐.𝟓𝐊 𝐐𝐇𝐃 & 𝐂𝐨𝐥𝐨𝐫 𝐍𝐢𝐠𝐡𝐭 𝐕𝐢𝐬𝐢𝐨𝐧 — Experience crystal-clear visibility day and night with full-color night vision enhanced by a built-in white light. Perfect as a baby monitor, pet camera, or security camera to monitor your home inside and out
- 𝐒𝐦𝐚𝐫𝐭 𝐀𝐈 𝐃𝐞𝐭𝐞𝐜𝐭𝐢𝐨𝐧 & 𝐀𝐥𝐞𝐫𝐭𝐬 — Stay informed about what matters most with human/motion/sound detection up to 33 feet away. The camera deters intruders with flashing lights and a siren while sending instant alerts to your phone — keeping you one step ahead of any suspicious activity. Call +1 (978) 437-5767 for expert support with setting up and optimizing Vimtag cameras, available Monday to Friday, 9:00 AM - 6:00 PM (ET)
- 𝐄𝐧𝐡𝐚𝐧𝐜𝐞𝐝 𝐓𝐰𝐨-𝐖𝐚𝐲 𝐀𝐮𝐝𝐢𝐨 - Communicate effortlessly with guests or check in on pets using the upgraded two-way audio feature of this indoor camera, allowing you to see, hear, and speak from anywhere
- 𝐓𝐰𝐨 𝐑𝐞𝐜𝐨𝐫𝐝𝐢𝐧𝐠 𝐎𝐩𝐭𝐢𝐨𝐧𝐬 & 𝐑𝐞𝐚𝐥-𝐓𝐢𝐦𝐞 𝐒𝐡𝐚𝐫𝐢𝐧𝐠 - With the mobile app, you can access the baby camera's video anytime, anywhere, view real-time footage, and even share monitoring content with family, keeping you informed about your home dynamics while you're away.Enjoy secure cloud recording with Vimtag Cloud (subscription required) for detecting people, sounds, motion. Alternatively, you can insert a microSD card (sold separately) for local video storage
What did the 2019 report find?
Paul Marrapese’s internet scan identified more than 2 million vulnerable devices, according to SecurityWeek’s 2019 account. The report relayed that 39% of the scanned devices were in China, 19% in Europe and 7% in the United States, and that nearly half were made by Hichip. These figures were attributed to Marrapese through SecurityWeek’s account of his discussion with KrebsOnSecurity. They describe his historical scan, not a current census or estimate of present-day exposure.
How could the iLnkP2P flaws enable remote attacks?
CVE-2019-11219: finding exposed devices
CVE-2019-11219 was described as an enumeration flaw: it could help an attacker quickly discover internet-exposed devices using the system. Finding devices could make it easier to identify targets at scale.
CVE-2019-11220: interfering with a connection
CVE-2019-11220 could let an attacker intercept a connection and carry out a man-in-the-middle attack. The report said this could expose a device password and enable hijacking. An attacker did not need to be on the victim’s local network, but needed the P2P server’s IP address and the target device’s UID.
Rank #2
- Continuously Powered by Solar: Just 3 hours of sunlight is enough to keep the camera running. The tiny size and wire-free design allow it to be installed anywhere.
- Day and Night Clarity: Enjoy clear black-and-white night vision thanks to infrared LEDs and an f/1.6 aperture. Please note that spotlight color night vision is not supported.
- Easy Installation: Use anywhere thanks to its tiny size and wire-free design. Drill one hole, once.
- Human Detection: Al alerts you to anyone in your yard, whether family, a courier, or a stranger. Connect to HomeBase 3 for individual facial recognition.
- No Monthly Fee: One-time purchase. No monthly fees or hidden costs. On-device storage and AI for complete security and transparency.
Marrapese said the flaws could be combined: one could help locate devices, while the other could interfere with connection setup. In his explanation quoted by SecurityWeek, an attacker could influence a connection so that a user connected to the attacker instead of the device, allowing credentials to be captured.
How can I tell whether my camera uses iLnkP2P?
Start with the exact product, rather than assuming that a device is affected because it is an internet-connected camera or has a brand listed in the 2019 report. Check its model number and firmware details, then look for documentation or support information identifying the connection service it uses. The report also pointed to device UID prefixes, which may be printed on a product label, as a clue that a device could be vulnerable. A UID prefix is a screening clue, not confirmation that a specific model or firmware remains vulnerable.
Ask the manufacturer or seller for model-specific answers to these questions:
Rank #3
- High-definition pan and tilt camera: Capture every detail in pristine 1080p HD quality, from any angle, with the Energizer Connect security camera's 355-degree horizontal and 48-degree vertical pan and tilt capabilities.
- Night Vision Equipped: Camera has 4 led lights and 4 IR lights that switch automatically depending on the lighting conditions, allowing you to see color at night or black and white in total darkness.
- Two-Way Audio: Allowing you to listen and talk to the person in the video, using the built-in microphone and speaker, or siren alarm to deter intruders.
- Flexible Storage Options: Choose cloud storage with a complimentary 30-day trial or utilize a micro SD card (up to 128GB, not included) for local recording.
- 2.4GHz Wi-Fi Compatible: Connects to your 2.4ghz wifi network, which is the most common wifi frequency. It does not support 5ghz wifi networks.
- Does this exact model use iLnkP2P?
- Does its current firmware address CVE-2019-11219 and CVE-2019-11220?
- Is the model still supported, and where can you obtain security updates?
- Can remote or P2P access be disabled or restricted?
The available 2019 report did not provide a current vendor-by-vendor patch inventory. It said patches were not available when the report was published; that historical status does not establish whether a particular device has since been updated or remains unsupported.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should I do if my device may be affected?
- Identify the device. Record the manufacturer, exact model, firmware version and, if relevant, the UID prefix. Use the product label, device settings or manufacturer documentation.
- Check current support. Consult the manufacturer’s official support and security-update information for that model. If the status is unclear, ask whether the firmware fixes the two CVEs and whether the product still receives security updates.
- Limit exposure while you verify. If the device offers a way to disable remote or P2P access, consider turning it off until you understand its support status. The 2019 report also identified restricting external access to UDP port 32100 as a way to prevent outside networks from reaching affected devices over P2P. That is historical mitigation advice; apply network restrictions only if you can do so safely and understand the effect on device connectivity.
- Replace an unsupported device if its risk cannot be addressed. Marrapese recommended discarding affected vulnerable products and buying replacements. If the manufacturer cannot confirm a fix or continued support, replacement is a reasonable option. Compare the exact model’s update support, remote-access controls and network requirements; the cited sources do not establish that any particular current camera is secure.
How can network controls reduce IoT risk?
Network-level restrictions can limit what a connected device is allowed to communicate with, but they do not repair vulnerable software. NIST SP 1800-15 describes Manufacturer Usage Description (MUD), an approach that lets a network permit an IoT device’s necessary communications for its intended function while prohibiting other traffic. This is general defense-in-depth guidance, not an iLnkP2P patch.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Is the ThroughTek Kalay issue the same vulnerability?
No. Mandiant’s August 2021 report concerned CVE-2021-28372 in ThroughTek’s separate Kalay platform, not iLnkP2P. Mandiant said an attacker with a device UID could maliciously register a device and redirect client connections, potentially capturing credentials and gaining access to audio, video or further device functions. It reported more than 83 million active devices on Kalay at the time, while noting it could not compile a complete list of affected products. That platform-specific historical figure is not an iLnkP2P count, and Kalay’s recommended SDK and AuthKey/DTLS controls should not be treated as iLnkP2P fixes.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

