Vulnerability Description
A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V380 IP Camera firmware AppFHE1_V1.0.6.020230803 enables unauthenticated network actors to bypass the device’s credential-enforced live-view workflow and directly retrieve real-time video stream data.
Related Weaknesses (CWE)
References
- https://github.com/AounShAh/Research-on-v380-cctv-ip-camera#broken-access-contro
- https://github.com/AounShAh/Research-on-v380-cctv-ip-camera#broken-access-contro
FAQ
What is CVE-2026-12527?
CVE-2026-12527 is a documented vulnerability. A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V380 IP Camera firmware AppFHE1_V1.0.6.020230803 enables unauthenticated network a...
How severe is CVE-2026-12527?
CVSS scoring is not yet available for CVE-2026-12527. Check NVD for updates.
Is there a patch for CVE-2026-12527?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.