The Survision LPR Camera system does not enforce password protection by default. This allows access to the configuration wizard immediately without a login prompt or credentials check.
Advisories

No advisories yet.

Fixes

Solution

Survision has released the following versions for users to update to: * License Plate Recognition LPR Camera: Firmware version v3.5 Survision recommends users to enable the configuration password authentication by defining users and roles with minimal rights in the user management system and, where possible, enforce client certificate authentication. For future deployments, plan for integration of the new login/password mechanism and update your installation procedures accordingly. * On previous versions (inferior to 3.5) Survision recommends activating the "lock" password in the security parameters and, where possible, enforce client certificate authentication. For more information, contact Survision https://survisiongroup.com/post-contact .


Workaround

No workaround given by the vendor.

History

Wed, 05 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Nov 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Survision
Survision license Plate Recognition Camera
Vendors & Products Survision
Survision license Plate Recognition Camera

Tue, 04 Nov 2025 19:00:00 +0000

Type Values Removed Values Added
Description The Survision LPR Camera system does not enforce password protection by default. This allows access to the configuration wizard immediately without a login prompt or credentials check.
Title Missing Authentication for Critical Function Survision License Plate Recognition Camera
Weaknesses CWE-306
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-11-05T14:46:47.761Z

Reserved: 2025-10-23T13:00:09.658Z

Link: CVE-2025-12108

cve-icon Vulnrichment

Updated: 2025-11-05T14:46:44.099Z

cve-icon NVD

Status : Received

Published: 2025-11-04T19:17:09.740

Modified: 2025-11-04T19:17:09.740

Link: CVE-2025-12108

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-05T10:47:19Z