CVE-2018-12674: SV3C h.264 Poe IP Camera Firmware
Medium severity, CVSS 5.7. EPSS: 0.6% chance of exploitation in the next 30 days.
The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) stores the username and password within the cookies of a session. If an attacker gained access to these session cookies, it would be possible to gain access to the username and password of the logged-in account.
Affected products
- SV3C h.264 Poe IP Camera Firmware: version v2.3.4.2103-s50-ntd-b20170508b only; version v2.3.4.2103-s50-ntd-b20170823b only
Published 2018-10-19. Last modified 2026-06-17.