Flock Cameras in Deer Park

What Deer Park bought, what it costs, and what the record shows

The security record

The federal government's vulnerability database lists 15 security flaws in Flock Safety devices, two of them rated 9.8 out of 10. Flock's answer is that exploiting them requires physical access and expert knowledge of its hardware, and that no customer action is required. Both of those things are on the record, and both belong on this page.

What is in the federal database

The National Vulnerability Database is run by the National Institute of Standards and Technology. It is the United States government's catalog of publicly disclosed software and hardware vulnerabilities. Searching it for "Flock Safety" returns 15 records.1

We re-ran that query on July 29, 2026 and confirmed the count and every severity rating below.

Flock Safety records in the National Vulnerability Database, retrieved July 29, 20261
Identifier Severity Score Device What it is
CVE-2025-47818 LOW 2.2 Gunshot Detection Devices before version 1.3 have a hard-coded password for a connection.
CVE-2025-47819 MEDIUM 6.4 Gunshot Detection Devices before version 1.3 have an on-chip debug interface with improper access control.
CVE-2025-47820 LOW 2 Gunshot Detection Devices before version 1.3 store code in cleartext.
CVE-2025-47821 LOW 2.2 Gunshot Detection Devices before version 1.3 have a hardcoded password for a system.
CVE-2025-47822 MEDIUM 6.4 License Plate Reader Plate readers with firmware through 2.2 have an on-chip debug interface with improper access control.
CVE-2025-47823 LOW 2.2 License Plate Reader Plate readers with firmware through 2.2 have a hardcoded password for a system.
CVE-2025-47824 LOW 2 License Plate Reader Plate readers with firmware through 2.2 store code in cleartext.
CVE-2025-59402 MEDIUM 5.4 Bravo Edge AI Compute Device Accepts the default Thundercomm Firehose loader in EDL/QDL mode, letting an attacker with physical access flash arbitrary firmware, dump partitions, and bypass bootloader and OS security controls.
CVE-2025-59403 CRITICAL 9.8 Falcon, Sparrow, and Bravo devices The Android "Collins" application responsible for the camera feed lacks authentication and exposes administrative API endpoints on port 8080, including /reboot, /logs, /crashpack, and /adb/enable. NVD describes the impacts as denial of service, information disclosure, and remote code execution, with /adb/enable giving an attacker on the same LAN or WLAN shell access.
CVE-2025-59404 HIGH 7.5 Bravo Edge AI Compute Device Ships with its bootloader unlocked, permitting bypass of Android Verified Boot and direct modification of partitions.
CVE-2025-59405 HIGH 7.5 Falcon and Sparrow plate readers, Bravo devices The "Peripheral" Android application contains a cleartext DataDog API key in its codebase, recoverable by decompiling the app.
CVE-2025-59406 MEDIUM 6.2 Falcon and Sparrow plate readers, Bravo devices The "Pisco" Android application contains a cleartext Auth0 client secret in its codebase, recoverable by decompiling the app.
CVE-2025-59407 CRITICAL 9.8 Falcon and Sparrow plate readers, Bravo devices The "DetectionProcessing" Android application bundles a Java keystore (flock_rye.bks) together with its hardcoded password (flockhibiki17). The keystore contains a private key.
CVE-2025-59408 HIGH 7.3 Bravo Edge AI Compute Device Ships with Secure Boot disabled, allowing an attacker to flash modified firmware with no cryptographic protections.
CVE-2025-59409 HIGH 7.5 Falcon and Sparrow plate readers Ship with development Wi-Fi credentials (test_flck) stored in cleartext in production firmware.

Severity totals: 2 critical, 4 high, 4 medium, 5 low.1

The two critical ones, in plain terms

CVE-2025-59403 — CVSS 9.8. The Android application that runs the camera feed on Falcon, Sparrow, and Bravo devices lacks authentication, exposing administrative API endpoints on port 8080 — including the ability to enable Android Debug Bridge, the developer tool that grants command-level control of a device.1

CVE-2025-59407 — CVSS 9.8. The software bundles a Java keystore file containing a private key, together with its hardcoded password.1 A hardcoded credential shipped inside distributed software is not a secret; it is a published one.

A 9.8 rating on a 10-point scale is close to the maximum. That score reflects what an attacker could do if they reach the interface — not how easy reaching it is, which is exactly the point Flock makes in response.

Flock Safety's response, quoted

Flock published a response to this research on November 6, 2025. Its core argument:

would not only require physical access to a device Flock Safety, Response to compiled security research on Flock Safety devices2

and further, that exploitation would require

intimate knowledge of internal device hardware Flock Safety2

The company also stated:

none of the vulnerabilities detailed in the report have an impact on our customers' ability to carry out Flock Safety, on customers' public safety objectives2

and concluded:

No customer action is required. Flock Safety2

To Flock's credit, and this should be said plainly: the company registered these vulnerabilities as CVEs through MITRE itself, and has pledged to CISA's Secure By Design initiative.2 A vendor that files its own CVEs is behaving better than one that buries them.

Where that response is weakest

Flock's defense rests on physical access being hard. Two things complicate it.

First, these cameras are mounted in public right-of-way. A Flock Falcon sits on a pole beside a road, powered by solar, reachable by anyone who walks up to it. "Requires physical access" is a strong mitigation for a server in a locked data center. It is a much weaker one for hardware bolted to a residential street. Deer Park's nine cameras are, by design, in places the public can reach.

Second, at least some Flock cameras have been reachable over the internet without authentication. 404 Media documented cameras left streaming publicly, found by the musician and researcher Benn Jordan.3

The account security problem

The device vulnerabilities are not the whole picture. In November 2025, Senator Ron Wyden and Representative Raja Krishnamoorthi wrote to the Federal Trade Commission about Flock's platform security, reporting that the system did not require multi-factor authentication and that more than 35 accounts were found with stolen passwords.4,5

This matters more for a small department than a large one. A single compromised login to a Flock account can search that account's cameras. If Deer Park's nine cameras are enrolled in any shared or national lookup arrangement — and nobody has told residents whether they are — the exposure is not limited to Deer Park's own officers' credentials.

What this means for a nine-camera city

We are not arguing that Deer Park's cameras have been hacked. We have no evidence of that, and we would say so if we did.

The argument is narrower and, we think, harder to dismiss:

  1. These devices have a documented vulnerability history, including two near-maximum severity ratings.1
  2. The vendor's mitigation argument depends on physical access being difficult, and this hardware is installed on public streets.
  3. The platform has had credential-security problems flagged by members of Congress.4
  4. Deer Park has no published policy requiring anything of the vendor — no security standard, no breach notification, no audit right, no penalty.6

Cleveland's council addressed point four directly. When it renewed its Flock contract in July 2026, it added a contractual penalty of up to 25 percent of the contract value for violations of the privacy and data-sharing provisions, along with warrant-only disclosure and quarterly written reports to council.7

Deer Park's contract, as far as the public record shows, contains none of that. We do not know for certain, because the contract has never been published. Asking for it is the first step.

Sources

  1. Federal vuln. database Search for "Flock Safety" in the National Vulnerability Database. National Institute of Standards and Technology. Queried July 29, 2026. nvd.nist.gov/vuln/search/results?query=Flock+Safety 123456789A search of the federal government's vulnerability database for "Flock Safety" returned 15 records on July 29, 2026. We counted them from the database itself, not from anyone's summary of it.Retrieved July 29, 2026.
  2. Flock Safety Response to compiled security research on Flock Safety devices. Flock Safety. November 6, 2025. www.flocksafety.com/blog/response-to-compiled-security-research-on-flock-safety-devices 12345Retrieved July 29, 2026.
  3. News reporting How Benn Jordan Discovered Flock's Cameras Were Left Streaming to the Internet. 404 Media. 2026. www.404media.co/how-benn-jordan-discovered-flocks-cameras-were-left-streaming-to-the-internet 12Concerns Flock's Condor pan-tilt-zoom cameras, which are a different product from the Falcon plate readers.Retrieved July 29, 2026.
  4. Government record Letter to the Federal Trade Commission on Flock Safety's data security practices. U.S. Senator Ron Wyden and U.S. Representative Raja Krishnamoorthi. November 3, 2025. www.wyden.senate.gov/imo/media/doc/wyden_letter_to_ftc_on_flockpdf.pdf 12Retrieved July 29, 2026.
  5. Government record Wyden, Krishnamoorthi Urge FTC to Investigate Surveillance Tech Company on Negligently Handling Americans' Personal Data. Office of U.S. Senator Ron Wyden. November 3, 2025. www.wyden.senate.gov/news/press-releases/wyden-krishnamoorthi-urge-ftc-to-investigate-surveillance-tech-company-on-negligently-handling-americans-personal-data Retrieved July 29, 2026.
  6. Government record Police Department. City of Deer Park, Ohio. www.deerpark-oh.gov/departments/police Checked July 29, 2026 for any mention of ALPR, plate readers, Flock, or camera policy. None appears.Retrieved July 29, 2026.
  7. Government record Amendment to Ordinance No. 683-2026 (as amended, desk copy). Department of Law, City of Cleveland. July 15, 2026. cityofcleveland.legistar.com/View.ashx?M=F&ID=15693899&GUID=7AC8CF89-050A-435D-88A7-7C46EF9C7726 Two-page amendment signed by Assistant Director of Law Vishnu Ganglani. Cuts the term from one year to six months and the amount from $250,000 to $125,000; adds warrant-only disclosure, a penalty of up to 25 percent of the contract for privacy violations, a public transparency portal, quarterly written reports to the Clerk and Safety Committee, and a bar on sharing data with the Northeast Ohio Regional Fusion Center.Retrieved July 29, 2026.