In Ubitiquiti’s AirVision cameras, the RTSP stream is easily discovered and requires no authentication to view.

Example: For https://IP/login.cgi?uri=/ , if you do not have the login you cannot view the stream via the web portal, but if you go directly to the rtsp stream, rtsp://IP:554/live/ch00_0 , then you can view it with no login.

Discovery: I was curious how Shodan was able to pull down images from webcams that had a non-default authentication setup, but had their RTSP port exposed.