CVE-2018-12666: SV3C h.264 Poe IP Camera Firmware

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B devices improperly identifies users only by the authentication level sent in the cookies, which allow remote attackers to bypass authentication and gain administrator access by setting the authLevel cookie to 255.

Affected products

  • SV3C h.264 Poe IP Camera Firmware: version v2.3.4.2103-s50-ntd-b20170508b only; version v2.3.4.2103-s50-ntd-b20170823b only

Published 2018-10-19. Last modified 2026-06-17.