CVE-2019-10710: Hisilicon HI3510 Firmware

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Insecure permissions in the Web management portal on all IP cameras based on Hisilicon Hi3510 firmware allow authenticated attackers to receive a network's cleartext WiFi credentials via a specific HTTP request. This affects certain devices labeled as HI3510, HI3518, LOOSAFE, LEVCOECAM, Sywstoda, BESDER, WUSONGLUSAN, GADINAN, Unitoptek, ESCAM, etc.

Affected products

  • Hisilicon HI3510 Firmware: affected versions not specified

Published 2019-04-23. Last modified 2026-06-17.