CVE-2019-12920: Cylan Clever Dog Smart Camera Panorama Dog-2w Firmware

Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.

On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the network can login remotely to the camera and gain root access. The device ships with a hardcoded 12345678 password for the root account, accessible from a TELNET login prompt.

Affected products

  • Cylan Clever Dog Smart Camera Panorama Dog-2w Firmware: affected versions not specified
  • Cylan Clever Dog Smart Camera Plus Dog-2w-v4 Firmware: affected versions not specified

Published 2019-06-20. Last modified 2026-06-17.