Following an investigation by PCMag and Bitdefender, a patch has been issued for the Netatmo Smart Indoor Security Camera.
The Bitdefender IoT Vulnerability Research Team discovered that the device is susceptible to an authenticated file write that leads to command execution (CVE-2019-17101), as well as to a privilege escalation via dirtyc0w—a local privilege escalation bug that exploits a race condition in the implementation of the copy-on-write mechanism in the kernel’s memory-management subsystem.
Many smart home devices are notoriously insecure, and this is the main reason why I don’t have any of them (Besides my robot vacuum, but I explained my reasoning).