Consumer IoT devices such as IP cameras pose significant security risks, especially once they have reached end-of-life where they stop receiving firmware updates. Despite these devices being implemented within homes and businesses, they are overlooked by current security standards, as they only target devices entering the market. This project addresses that gap by penetration testing the TP-Link NC200 IP camera (firmware 2.1.13, end-of-life), using PTES as the primary methodology, with OWASP IoT Top 10 for classification, CVSS 4.0 for risk scoring, and ETSI EN 303 645 for compliance benchmarking. Testing has been carried out in an isolated environment, with the assumption that the attacker is already on the network. Fourteen vulnerabilities were identified, spanning six OWASP categories, ranging from default credentials and plaintext credential transmission to session hijacking, lack of brute force protections and denial of service attacks through input validation failure. CVSS 4.0 scoring rated one vulnerability as Critical, eight as High, and five as Medium. The NC200 was non-compliant with the majority of ETSI provisions encountered. The findings themselves demonstrate the compounding risks that come with legacy IoT devices in active deployment.