Sv3c manufactures a narrow line of IP camera products and firmware, primarily POE-based surveillance devices for small-business and residential deployment, with vulnerabilities that skew strongly toward critical severity. The recurring exposure centers on authentication bypass, credential exposure, command injection, and cross-site scripting within camera firmware and web interfaces—weaknesses characteristic of consumer-grade embedded devices with limited input validation and direct OS-level access. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sv3c over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12667CRITICAL The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) is affected by an improper authentication vulnerability that allows requests to be m | Oct 19, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-12675MEDIUM The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) does not perform origin checks on URLs that the camera's web interface redirects a u | Oct 19, 2018 | 6.1 | 30 | NO | YES |
CVE-2018-12670CRITICAL SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B devices allow OS Command Injection. | Oct 19, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-12671CRITICAL An attacker with remote access to the SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) web interface can disclose information about the c | Oct 19, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-12668CRITICAL SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B devices have a Hard-coded Password. | Oct 19, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-12666CRITICAL SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B devices improperly identifies users only by the authentication level sent in the cookies, which allow remote attackers to byp | Oct 19, 2018 | 9.8 | 28 | NO | NO |
CVE-2018-12669HIGH SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B devices allow remote authenticated users to reset arbitrary accounts via a request to web/ | Oct 19, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-12673HIGH An attacker with remote access to the SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) web interface can disclose information about the c | Oct 19, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-12674MEDIUM The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) stores the username and password within the cookies of a session. If an attacker gai | Oct 19, 2018 | 5.7 | 20 | NO | NO |
CVE-2018-12672MEDIUM The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B) does not perform proper validation on user-supplied input and is vulnerable to cross-site scripting attacks. If proper | Oct 19, 2018 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sv3c.
Media articles that mention a CVE ID that affects a product developed by Sv3c — matched by CVE ID, not by vendor name.