CVE-2018-18602: Critical severity guardzilla 360 outdoor vulnerability

Published Dec 31, 2018
·
Updated

The Cloud API on Guardzilla smart cameras allows user enumeration, with resultant arbitrary camera access and monitoring.

Affected Software

24 affected components
Guardzilla 360 Outdoor Firmware
Guardzilla 360 Outdoor
Guardzilla 180 Outdoor Firmware
Guardzilla 180 Outdoor
Guardzilla 360 Indoor Firmware
Guardzilla 360 Indoor
Guardzilla 180 Indoor Firmware
Guardzilla 180 Indoor
Guardzilla Outdoor Hd Camera Firmware
Guardzilla Outdoor Hd Camera
Guardzilla Indoor Hd Camera Firmware
Guardzilla Indoor Hd Camera
All of the following
Guardzilla 360 Outdoor Firmware
Guardzilla 360 Outdoor
All of the following
Guardzilla 180 Outdoor Firmware
Guardzilla 180 Outdoor
All of the following
Guardzilla 360 Indoor Firmware
Guardzilla 360 Indoor
All of the following
Guardzilla 180 Indoor Firmware
Guardzilla 180 Indoor
All of the following
Guardzilla Outdoor Hd Camera Firmware
Guardzilla Outdoor Hd Camera
All of the following
Guardzilla Indoor Hd Camera Firmware
Guardzilla Indoor Hd Camera

Event History

Dec 31, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2018-18602?

CVE-2018-18602 has a medium severity due to the potential for unauthorized camera access and monitoring.

2

How do I fix CVE-2018-18602?

To mitigate CVE-2018-18602, it is recommended to update the firmware of the affected Guardzilla smart cameras.

3

What exploit does CVE-2018-18602 enable?

CVE-2018-18602 enables user enumeration, which can lead to arbitrary access to camera feeds and monitoring.

4

Which devices are affected by CVE-2018-18602?

CVE-2018-18602 affects various Guardzilla smart cameras, including the 360 Outdoor and 180 Outdoor models.

5

Is CVE-2018-18602 a permanent vulnerability?

No, CVE-2018-18602 can be addressed by applying the appropriate firmware updates provided by Guardzilla.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203