

You will not like this answer:
An old 11” macbook air or the 12” macbook circa ‘17.
They’re everywhere, last forever, parts are cheap, they’re durable, there is good Linux support, the screens are good and they don’t stick out when you’re using them in public.
I used to have 11” as my hard upper limit of diagonal size years ago but since then I realized it’s no big deal to carry a 13” diagonal computer now that they’re all incredibly thin and light.

They use networking software that’s optimized for speed and low resource use (you’d rather be spending those arm/esp cycles handling video, right?) with a slow patch cycle and little chance the user (you!) will actually get up on a ladder and install the damn patches.
Some of them will dial out and try to get their patches, but did it work? Are they still running right after the patch? You don’t know that because you don’t even know they got a patch notification, dialed out, downloaded and installed it, silently changed a default or removed a resolution you relied on and aren’t sending video anymore! Do you even want them doing that?
Even if they weren’t doing all that, there are hundreds of vulnerabilities that allow a user on the local network to silently bypass auth and view them, change settings etc.
The above isn’t because they’re crappy (they are crappy.) but because they’re using some weird .005$ cheaper esp32 variant that needs a modified binary which isnt on anyone’s radar and had support dropped 2 years ago.
I have even run into modern ip cameras that would try to proxy their feed on a public facing ip that used to be owned by the (now defunct) manufacturer but is now some weirdo just slurping up what gets sent to them.
The simple solution is to put them on a derek zoolander vlan for network devices that can’t network good, cut em off from the outside world and check for updates manually.