.. / CVE-2018-12675

Exploit for SV3C HD Camera L Series - Open Redirect (CVE-2018-12675)

Description:

SV3C HD Camera L Series 2.3.4.2103-S50-NTD-B20170508B and 2.3.4.2103-S50-NTD-B20170823B contains an open redirect vulnerability. It does not perform origin checks on URLs in the camera’s web interface, which can be leveraged to send a user to an unexpected endpoint. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

Nuclei Template

View the template here CVE-2018-12675.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2018/CVE-2018-12675.yaml
Copy

References:

https://vuldb.com/?id.125799
https://www.bishopfox.com/news/2018/10/sv3c-l-series-hd-camera-multiple-vulnerabilities/
https://nvd.nist.gov/vuln/detail/CVE-2018-12675
https://github.com/ARPSyndicate/kenzer-templates
https://bishopfox.com/blog/sv3c-l-series-hd-camera-advisory