Counter-Surveillance & Privacy Law · Updated October 1, 2026

Finding cameras on a Wi-Fi network you control vs one you don’t

6 min read By the TrueSpyTech team
Finding cameras on a Wi-Fi network you control vs one you don’t
Photo: Siarhei Horbach horbach · Public domain
TrueSpyTech is reader-supported. When you buy through links on our site, we may earn an affiliate commission. This doesn’t affect our verdicts.

On a network you control, finding a hidden Wi-Fi camera is mostly bookkeeping: log in to the router, read the list of connected devices, and account for every one. On a network you do not control, such as a hotel’s or a short-term rental host’s, you cannot do that, and you should not try to probe it. What you can do is listen passively for devices around you, which is what a 2022 research system called Lumos does, though it is a research prototype and not a store-bought app.

The two situations call for different tools and carry different legal risk, so this article keeps them apart. If your only question is whether your own home network has a camera on it that you did not put there, jump to the first section.

On your own network: read the device list

Every router keeps a table of connected devices, usually under a heading like “connected devices,” “client list” or “DHCP clients.” Log in to the router’s admin page (the address and password are often printed on the router’s label, and if you never changed the default password, change it today). Write down each entry: the name, the IP address and the MAC address.

Then work through them. Your phones, laptops, TV and consoles are easy. The harder entries are the ones with names like “ESP_3A91F2” or no name at all. Many cheap cameras identify themselves with a generic chip name or a string of letters. The first six characters of a MAC address identify the manufacturer, and the IEEE publishes a public registry of these prefixes, so a lookup often tells you who made the network card. A device from a camera or IoT chip maker that you cannot match to anything you own is a lead, not a verdict.

To test a suspect, turn devices off one at a time, or unplug the plug-in items in a room, and refresh the list. The entry that disappears when you unplug the “phone charger” in the hallway tells you something. If an entry goes away only when you cut power to a smoke detector or a clock, you have found a camera.

Checking for streaming services

Some IP cameras expose a video stream using the Real Time Streaming Protocol. IANA’s service registry lists RTSP on port 554 (TCP and UDP) and an alternate on port 8554. A port scanner run from a computer on your own network against your own devices can show which of them answer on those ports. A device that answers on 554 and that you cannot account for is very likely a camera or a recorder.

The caveat is that many modern cameras do not accept direct connections at all. They call out to the manufacturer’s cloud and wait there, so there is nothing listening on 554. That is why the device list, not the port scan, is the primary check.

Guest networks and what they hide

Many routers put guests on a separate network that cannot see your main devices. This is good for security and bad for a hunt: if a camera is on the host’s main network and you are on the guest network, the device list you can reach, if any, will not include it. Do not take a clean guest-side scan as evidence that nothing is there.

On a network you do not control: do not scan it

Port-scanning or probing devices on a hotel or rental network is a bad idea beyond the practical limits. The Computer Fraud and Abuse Act, 18 U.S.C. section 1030, makes it an offense to intentionally access a computer without authorization, or to exceed authorized access, and obtain information from a protected computer. The statute defines “exceeds authorized access” as accessing a computer with authorization and using that access to obtain or alter information that the accesser is not entitled to obtain or alter. A guest password gives you internet access. It does not obviously give you permission to poke at the host’s cameras, and “I was looking for a spy camera” is not an exception written into the statute. Whether a given scan would be charged is a question for a lawyer; the sensible position is not to put yourself in the argument.

The same goes for logging in to a camera’s app or cloud account if you find the device. That is the police’s job, with the owner’s account, under a warrant if needed.

What passive listening can do

The Lumos paper, presented at USENIX Security 2022, takes a different approach to the unfamiliar-network problem. Instead of connecting, it listens to the encrypted 802.11 Wi-Fi packets in the air and uses what the unencrypted 802.11 headers and the traffic pattern reveal to guess what kind of device sent them. The authors report identifying device types with 95 percent accuracy in under 30 minutes, and locating them with a median error of 1.5 meters after one walk around the perimeter of a space of about 1,000 square feet. Those figures come from six test environments and 44 devices.

Read the limits as carefully as the headline number. The system targets Wi-Fi devices only, so a camera on Ethernet, or one recording to a card, is invisible to it. The prototype ran on a laptop, or on an iPhone paired with a Raspberry Pi over Bluetooth, because the authors note that promiscuous Wi-Fi sniffing is disabled on mobile phones. Their code is released for researchers; it is not a consumer product you install from an app store. Any app that claims to deliver the same result from a phone alone deserves skepticism.

What a normal traveler can do

Not much on the network side, and that is fine. Look at what the listing or hotel says about cameras, run the lens check and a radio sweep, and check whether anything plugged into a wall socket points at the bed. Our guide to a hotel or Airbnb sweep lays out the physical routine. If your phone’s Wi-Fi settings show a network named like a camera, that is worth noting, but a network name is only a hint.

Your own home: a routine worth repeating

  • Check the router’s device list every few months and after anyone else has had access to your Wi-Fi password.
  • Change the password if you cannot account for a device, then see which devices reconnect.
  • Give smart devices their own guest network where the router allows it.
  • Keep a list of what you own so a stranger in the table stands out.

For the case where the camera is yours and the question is where it records, our comparison of Wi-Fi and SD card cameras explains why some never touch the network at all. For the wider routine, see the counter-surveillance guide.

Behind this review

TrueSpyTech does not operate a test lab, and no article here rests on a unit we plugged in ourselves. Research pulls the spec sheets and the relevant law, the pattern in owner reports fills in what a spec sheet will not admit, and an editor signs off before anything goes live. Ratings are locked before affiliate links go in, never after. The full protocol is on our How we review page.

Google lets you pick which sites come up first in your own results.