CVE-2019-10711: Hisilicon HI3510 Firmware
High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.
Incorrect access control in the RTSP stream and web portal on all IP cameras based on Hisilicon Hi3510 firmware (until Webware version V1.0.1) allows attackers to view an RTSP stream by connecting to the stream with hidden credentials (guest or user) that are neither displayed nor configurable in the camera's CamHi or keye mobile management application. This affects certain devices labeled as HI3510, HI3518, LOOSAFE, LEVCOECAM, Sywstoda, BESDER, WUSONGLUSAN, GADINAN, Unitoptek, ESCAM, etc.
Affected products
- Hisilicon HI3510 Firmware: before 1.0.1 (fixed in 1.0.1)
Published 2019-04-23. Last modified 2026-06-17.