CVE-2017-3186 describes a critical vulnerability affecting ACTi D, B, I, and E series cameras running firmware A1D-500-V6.11.31-AC, where devices utilize non-random, default administrative credentials. This allows a remote attacker to gain complete control over affected cameras with low attack complexity. The vulnerability carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, requiring no user interaction and leading to high impacts on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, its high FAUCET Risk Score of 96/100 and significant community discussion (10 mentions) indicate considerable concern, despite no public exploit code (Metasploit, Nuclei, ExploitDB) or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
a1d-500-v6.11.31-acCPE matchmatch criteria | cpe:2.3:o:acti:camera_firmware:a1d-500-v6.11.31-ac:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.