CVE-2018-20955
Swann
- Published
- 8 August 2019
- Last modified
- 17 June 2026
- CVSS
- 9.8 v3.0
- Severity
- critical
- EPSS
- 2.0% (80th pct)
- CISA KEV
- Not listed
- NVD status
- Modified
- Weaknesses
- CWE-798
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Swann SWWHD-INTCAM-HD devices have the twipc root password, leading to FTP access as root. NOTE: all affected customers were migrated by 2020-08-31.
Exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalogue as of 2026.09.04. That is an absence of confirmed public exploitation, not evidence that exploitation has not occurred. EPSS models a 2.0% probability of exploitation activity in the next 30 days.
Affected products
| Product | Vendor | Type | Versions named |
|---|---|---|---|
| Swwhd-intcam-hd | Swann | unknown | — |
References
- https://www.pentestpartners.com/security-blog/hacking-swann-home-security-camera-video/ exploit
- https://www.swann.com/au/safe-by-swann-upgrade
- https://www.pentestpartners.com/security-blog/hacking-swann-home-security-camera-video/ exploit
- https://www.swann.com/au/safe-by-swann-upgrade
Record assembled from NVD, CISA KEV 2026.09.04 and FIRST EPSS 2026-09-04. Affected products are those NVD's CPE configuration names that fall inside this site's scope; a CVE may affect products outside it.