Description
A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V380 IP Camera firmware AppFHE1_V1.0.6.020230803 enables unauthenticated network actors to bypass the device’s credential-enforced live-view workflow and directly retrieve real-time video stream data.
Published: 2026-06-18
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 21 Jun 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Shenzhen Liandian
Shenzhen Liandian v380 Ip Camera
Vendors & Products Shenzhen Liandian
Shenzhen Liandian v380 Ip Camera

Thu, 18 Jun 2026 18:30:00 +0000

Type Values Removed Values Added
Title Broken Authorization Leading to Unauthenticated Live Video Exposure on V380 IP Camera

Thu, 18 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
Description A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V380 IP Camera firmware AppFHE1_V1.0.6.020230803 enables unauthenticated network actors to bypass the device’s credential-enforced live-view workflow and directly retrieve real-time video stream data.
Weaknesses CWE-306
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/S:P/AU:Y/V:C/U:Red'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Shenzhen Liandian V380 Ip Camera
cve-icon MITRE

Status: PUBLISHED

Assigner: Toreon

Published:

Updated: 2026-06-18T14:54:30.902Z

Reserved: 2026-06-17T13:45:59.689Z

Link: CVE-2026-12527

cve-icon Vulnrichment

Updated: 2026-06-18T14:54:24.767Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-20T22:56:04Z

Weaknesses