VYPR
Unrated severityNVD Advisory· Published Jun 18, 2026· Updated Jun 18, 2026

CVE-2026-12527

CVE-2026-12527

Description

A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V380 IP Camera firmware AppFHE1_V1.0.6.020230803 enables unauthenticated network actors to bypass the device’s credential-enforced live-view workflow and directly retrieve real-time video stream data.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

Root cause

"The RTSP streaming service bypasses authentication and authorization checks when enabled via a configuration flag, allowing unauthenticated access to the live video feed."

Attack vector

An unauthenticated network attacker first gains root shell access to the device, for example via the undocumented Telnet service with hard-coded credentials (CVE-2025-7503) [ref_id=1]. With root access, the attacker modifies the `rtsp_enable` value in `/mnt/mtd/mvconf/factory_const.ini` to 1 and reboots the camera. After reboot, the RTSP service starts and exposes the live video feed without requiring any credentials, allowing the attacker to directly retrieve real-time video stream data over the network [ref_id=1].

Affected code

The vulnerability resides in the RTSP streaming worker thread within the camera's main binary ("recorder"). The firmware reads the `rtsp_enable` flag from `/mnt/mtd/mvconf/factory_const.ini` and, when set to 1, starts the RTSP/ONVIF services without enforcing the normal authentication and authorization checks that protect the live video stream [ref_id=1].

What the fix does

The advisory does not provide a patch or vendor fix. The researcher notes that the vendor has not released any firmware updates or mitigations [ref_id=1]. To close the vulnerability, the camera's RTSP service would need to enforce the same authentication and authorization checks that protect the normal live-view workflow, rather than relying solely on a configuration flag that can be trivially modified by an attacker with root access.

Preconditions

  • networkAttacker must have network access to the camera
  • authAttacker must obtain root shell access (e.g., via the undocumented Telnet service with hard-coded credentials)
  • configAttacker must modify the rtsp_enable flag in factory_const.ini and reboot the device

Generated on Jun 19, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

News mentions

0

No linked articles in our index yet.