I now have three of these $120usd 'Jennov' branded (hik-vision bits and pieces) PTZ cameras:
https://www.amazon.com/gp/product/B07K9XXP69/ref=ppx_yo_dt_b_asin_title_o00_s00?ie=UTF8&psc=1
I purchased the first on a whim just to see how bad it was both from a functional point of view and a network security perspective. I was pretty certain it would be junk compared to the Reolink system I have.
I was pleasantly surprised, functionally it works rather well even if the 5MP claim is technically true but mostly useless. They do however do a great job at 4MP and the PTZ functionality is awesome and scriptable with a few curl
tricks. The low light capability is as good if not better then the Reolink systems, which makes sense since it is running on a generic M400 board camera. It is so good in low light I've used it to refine satellite orbits via observations. The camera can detect mag 2.5 - 3.0 satellites easily (3.5 or dimmer not so much).
Here's a sample from a 4MP source: https://www.youtube.com/watch?v=rGUQjnNpaWI
Here's a more recent sample recorded at 1080P in h.264 since editing h265 at 4MP is a royal PITA. https://www.youtube.com/watch?v=JKHi9dwBHzo
Also, because rockets are cool: https://www.youtube.com/watch?v=JKHi9dwBHzo :)
When I first put it online it went into a network alone with just a single 4 port switch and a spare laptop running Kali Linux from an image. I monitored, poked, and probed it for several days and didn't find anything concerning. No telnet, no SSH, no P2P attempts (once I turned it off), no unusual open ports, no attempts at uPNP, or any strangeness. The ports that were opened were secure enough, with the exception of the ONVIF port, it would accept incoming PTZ commands w/o authenticating, but I couldn't find a way to exploit it.
I also got a copy of the firmware and used binwalk
to unpack it and I'm exploring the contents to see what I can see, so far nothing obvious. https://i.imgur.com/FUdxxUa.png I actually would like to enable SSH so I can poke at its internals on live platform, which seems doable I just need to work up the courage to flash my version of the firmware to it! :)
And because I could, here's a horribly produced tear down video where I ramble on way to long as I tear it apart: https://www.youtube.com/watch?v=CEbvl-GoE8I
Also Also, not a shill, this is a hobby and I was pleasantly surprised at how decent this silly thing is. It is as good or better than the Reolink camera and I find its ability to not need an NVR and to instead dump the video onto an NFS share to be much simpler. Don't get me wrong, I like my Reolink NVR and Cameras as they just work and setting them up was painless.