CVE-2018-16546: Amcrest Ipc-HX1X3X-Lexus Eng N Amcrest
Medium severity, CVSS 5.9. EPSS: 1% chance of exploitation in the next 30 days.
Amcrest networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation, as demonstrated by Amcrest_IPC-HX1X3X-LEXUS_Eng_N_AMCREST_V2.420.AC01.3.R.20180206.
Affected products
- Amcrest Amcrest Ipc-HX1X3X-Lexus Eng N Amcrest: version v2.420.ac01.3.r.20180206 only
Published 2018-09-05. Last modified 2026-06-17.