CVE-2026-12527
Received
Received - Intake
Unauthenticated RTSP Stream Access in V380 IP Camera Firmware
Publication date: 2026-06-18
Last updated on: 2026-06-18
Assigner: Toreon
Description
Description
A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V380 IP Camera firmware AppFHE1_V1.0.6.020230803 enables unauthenticated network actors to bypass the deviceβs credential-enforced live-view workflow and directly retrieve real-time video stream data.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| shenzhen_liandian_communication_technology_ltd | v380_ip_camera | appfhe1_v1.0.6.020230803 |
| shenzhen_liandian_communication_technology_ltd | v380_ip_camera | kerfhe1_ptz_wifi_v3.1.1 |
| shenzhen_liandian_communication_technology_ltd | v380_ip_camera | hwfhe1_wf6_ptz_wifi_20201218 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |