Junglewise Threat Intelligence

CVE-2026-12527: Shenzhen Liandian V380 IP Camera auth bypass in RTSP pipeline

CVE-2026-12527 · Severity: info · CVSS 6 · Published 2026-06-18

Executive brief

A security flaw in the V380 IP camera allows unauthorized individuals on the same network to view live video feeds without a password. This bypasses the normal security login process, potentially leading to privacy violations and unauthorized surveillance of the camera's surroundings. The issue affects specific firmware versions of cameras manufactured by Shenzhen Liandian Communication Technology.

Technical details

A Missing Authentication for Critical Function (CWE-306) exists in the RTSP media delivery pipeline of the V380 IP camera firmware. The vulnerability is located in the 'AppFHE1_V1.0.6.020230803' version, where the device fails to enforce credential requirements for RTSP stream requests. An attacker on the adjacent network can directly interface with the RTSP service to retrieve real-time video data, bypassing the intended live-view authorization workflow. While the vendor contact information is limited, the vulnerability has been documented by third-party researchers.

Affected products

  • Shenzhen Liandian Communication Technology LTD V380 IP Camera firmware AppFHE1_V1.0.6.020230803

Timeline

  • 2026-06-18: advisory: CVE-2026-12527 published by Toreon via NVD

References