Skip to content
Threat Feed
critical advisory

Critical Authentication Bypass in Seetong Surveillance Devices

An unauthenticated remote code execution vulnerability (CVE-2026-100886) exists in the Debug Service component of multiple Seetong NVR/DVR models, allowing attackers to bypass authentication entirely.

CVE search metadata

CVE search record: CVE-2026-100886. Severity: critical. CVSS: 10.0. KEV: no. Product: T8108 (4.6.1.4-build202604241011), T8108P (4.6.1.4-build202604241011), T8116 (4.6.1.4-build202604241011), T8232 (4.6.1.4-build202604241011). Brief: Critical Authentication Bypass in Seetong Surveillance Devices. Brief link: https://feed.craftedsignal.io/briefs/2026-09-seetong-debug-service-vuln/

CVE-2026-100886 is a critical vulnerability (CVSS 10.0) affecting the Debug Service component in Seetong T8108, T8108P, T8116, and T8232 video surveillance devices running firmware version 4.6.1.4-build202604241011. The vulnerability allows an unauthenticated remote attacker to bypass authentication mechanisms. Because the Debug Service is improperly implemented, attackers can gain unauthorized access to the device management interface. With public exploit code currently available and no known vendor response or patch, these devices are highly susceptible to compromise. This is a severe risk for enterprise environments where these devices may be exposed to the public internet, as an attacker could gain full administrative control over the surveillance system, leading to unauthorized video monitoring, device re-configuration, or lateral movement into the local network.

Impact

The vulnerability allows full authentication bypass on affected Seetong video surveillance units. If exploited, an attacker gains unauthorized administrative access to the device. This enables the complete compromise of the hardware, potential access to live and recorded video feeds, and the ability to use the device as a pivot point for further attacks within the internal network. Given the critical severity and lack of vendor remediation, organizations utilizing these devices are at high risk of compromise.

Recommendation

Prioritize the isolation of affected Seetong surveillance devices from the public internet.

  • Move all vulnerable Seetong T8108, T8108P, T8116, and T8232 devices behind a firewall or VPN and restrict access to management and debug interfaces to trusted internal subnets.
  • Implement egress traffic filtering on the VLANs containing these devices to prevent them from participating in botnet activities if compromised.
  • Monitor network logs for unusual inbound traffic patterns specifically targeting diagnostic or debug ports typically associated with Seetong device management.

Immediate actions

Isolate Seetong devices from internet-facing network segments.

IT Operations 24h

Mitigations

Place device management interfaces behind a firewall or VPN.

immediate IT Operations

CVE-2026-100886