High severity7.5NVD Advisory· Published Apr 23, 2019· Updated Jun 17, 2026
CVE-2019-10711
CVE-2019-10711
Description
Incorrect access control in the RTSP stream and web portal on all IP cameras based on Hisilicon Hi3510 firmware (until Webware version V1.0.1) allows attackers to view an RTSP stream by connecting to the stream with hidden credentials (guest or user) that are neither displayed nor configurable in the camera's CamHi or keye mobile management application. This affects certain devices labeled as HI3510, HI3518, LOOSAFE, LEVCOECAM, Sywstoda, BESDER, WUSONGLUSAN, GADINAN, Unitoptek, ESCAM, etc.
Affected products
2- Range: <=V1.0.1
Patches
Vulnerability mechanics
References
1- dojo.bullguard.com/dojo-by-bullguard/blog/cam-hi-risk/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.