A critical vulnerability (CVE-2025-12108) has been identified in Survision License Plate Recognition (LPR) Cameras, where the system does not enforce password protection by default. This flaw allows anyone to access the configuration wizard without a login prompt or credentials, enabling full system access without authentication. The vulnerability is remotely exploitable, has a CVSS v4 score of 9.3, and affects all versions of the Survision LPR Camera prior to the release of a patched firmware.
The issue was reported by Souvik Kandar of Microsec and confirmed by both CISA and independent vulnerability databases. Survision has released firmware version v3.5 to address the vulnerability and recommends that users update their devices and enable configuration password protection. The affected cameras are deployed worldwide, including in critical infrastructure sectors, and the vendor is headquartered in France. Organizations using these cameras are urged to apply the firmware update and review their authentication settings to mitigate the risk of unauthorized access.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
CISA published ICS advisory ICSA-25-308-02 covering the Survision License Plate Recognition Camera vulnerability. The advisory formalized public reporting of the issue in an industrial control systems context.
A high-severity vulnerability, CVE-2025-12108, was publicly disclosed affecting Survision License Plate Recognition Camera products. The issue was described as missing authentication for a critical function.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.