I personally would set up an anonymous account and email the manufacturer, asking them about bug bounty without revealing anything. Say something like that you are a security researcher and wondering if they have a bug bounty program for security of their webcams.
If they are willing to pay you, set up a proof of concept to demonstrate that the exploit works (ask them to give you an ip of a publicly accessible cam under their control and send them the image capture), and then ask to be paid out in BTC. Do everything behind the VPN of course. Remember, the company can simply sue you without any reason for some bullshit "unauthorized computer use" on a whim by someone who doesn't understand technology, so remaining anonymous is essential.
If they don't have a bug bounty, disclose it to them first, and give them a timeline to fix the exploit with guidance on how to do so, after which you can publicly disclose it, with instructions on how to mitigate (probably set up firewall rules im guessing), along with publishing all of the communication chain between you.