CVE-2018-12675 describes an open redirect vulnerability in SV3C HD Camera L-SERIES firmware versions V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B. This flaw allows an attacker to redirect users to arbitrary, untrusted websites due to the camera's web interface failing to perform origin checks on URLs. Rated with a CVSS score of 6.1 (Medium), this vulnerability requires user interaction (UI:R) and can be exploited over the network (AV:N) with low attack complexity (AC:L). Successful exploitation could lead to information disclosure (C:L) and integrity compromise (I:L), as users might be tricked into visiting malicious sites. While there is no evidence of active exploitation or Metasploit modules, a Nuclei template exists for detecting this open redirect. Community discussion and media coverage are minimal, indicating low public awareness and a lack of widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
v2.3.4.2103-s50-ntd-b20170508bCPE matchmatch criteria | cpe:2.3:o:sv3c:h.264_poe_ip_camera_firmware:v2.3.4.2103-s50-ntd-b20170508b:*:*:*:*:*:*:* | ||
v2.3.4.2103-s50-ntd-b20170823bCPE matchmatch criteria | cpe:2.3:o:sv3c:h.264_poe_ip_camera_firmware:v2.3.4.2103-s50-ntd-b20170823b:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.