CVE-2018-12666 describes a critical authentication bypass vulnerability in SV3C L-SERIES HD Camera firmware versions, including sv3c h.264_poe_ip_camera_firmware and specific SV-B01POE, SV-B11VPOE, and SV-D02POE models. The flaw allows remote attackers to gain administrator access by manipulating the 'authLevel' cookie to '255', as the devices improperly rely solely on this client-side value for authentication. This vulnerability carries a CVSS v3 score of 9.8 (Critical), indicating a network-exploitable flaw with low attack complexity, requiring no user interaction, and leading to complete compromise of confidentiality, integrity, and availability. While no public exploit intelligence (Metasploit, Nuclei, ExploitDB) is currently available and there is minimal community discussion or media coverage, the high FAUCET Risk Score of 80/100 suggests a significant potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
v2.3.4.2103-s50-ntd-b20170508bCPE matchmatch criteria | cpe:2.3:o:sv3c:h.264_poe_ip_camera_firmware:v2.3.4.2103-s50-ntd-b20170508b:*:*:*:*:*:*:* | ||
v2.3.4.2103-s50-ntd-b20170823bCPE matchmatch criteria | cpe:2.3:o:sv3c:h.264_poe_ip_camera_firmware:v2.3.4.2103-s50-ntd-b20170823b:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.