VYPR
Vendor

Foscam

Products
70
CVEs
71
Across products
177
Status
Private

Products

70
View all 70 products →

Recent CVEs

71
View all 71 CVEs →
  • CVE-2017-2805CriJun 21, 2017
    risk 0.66cvss 9.8epss 0.26

    An exploitable stack-based buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera. A specially crafted http request can cause a stack-based buffer overflow resulting in overwriting arbitrary data on the stack frame. An…

  • CVE-2017-5674CriMar 13, 2017
    risk 0.65cvss 9.8epss 0.22

    A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft a malformed HTTP ("GET system.ini HTTP/1.1\n\n" - note the lack of "/" in the path field of the request) request that will…

  • CVE-2021-43517CriApr 8, 2022
    risk 0.64cvss 9.8epss 0.02

    FOSCAM Camera FI9805E with firmware V4.02.R12.00018510.10012.143900.00000 contains a backdoor that opens Telnet port when special command is sent on port 9530.

  • CVE-2019-11560CriMay 7, 2019
    risk 0.64cvss 9.8epss 0.02

    A buffer overflow vulnerability in the streaming server provided by hisilicon in HI3516 models allows an unauthenticated attacker to remotely run arbitrary code by sending a special RTSP over HTTP packet. The vulnerability was found in many cameras using hisilicon's hardware and…

  • CVE-2018-19082CriNov 7, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SetDNS method allows remote attackers to conduct stack-based buffer overflow attacks via the IPv4Address field.

  • CVE-2018-19081CriNov 7, 2018
    risk 0.64cvss 9.8epss 0.05

    An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SetDNS method allows remote attackers to execute arbitrary OS commands via the IPv4Address field.

  • CVE-2018-19078CriNov 7, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The response to an ONVIF media GetStreamUri request contains the administrator username and password.

  • CVE-2018-19076CriNov 7, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The FTP and RTSP services make it easier for attackers to conduct brute-force…

  • CVE-2018-19069CriNov 7, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The CGIProxy.fcgi?cmd=setTelnetSwitch feature is authorized for the root user…

  • CVE-2018-19067CriNov 7, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. There is a hardcoded Ak47@99 password for the factory~ account.

  • CVE-2018-19064CriNov 7, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ftpuser1 account has a blank password, which cannot be changed.

  • CVE-2018-19063CriNov 7, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The admin account has a blank password.

  • CVE-2017-2877CriSep 19, 2018
    risk 0.64cvss 9.8epss 0.02

    A missing error check exists in the Multi-Camera interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. A specially crafted request on port 10001 could allow an attacker to reset the user accounts to factory defaults, without authentication.

  • CVE-2016-8731CriJun 21, 2017
    risk 0.64cvss 9.8epss 0.03

    Hard-coded FTP credentials (r:r) are included in the Foscam C1 running firmware 1.9.1.12. Knowledge of these credentials would allow remote access to any cameras found on the internet that do not have port 50021 blocked by an intermediate device.

  • CVE-2022-28743CriApr 21, 2022
    risk 0.59cvss 9.1epss 0.01

    Time-of-check Time-of-use (TOCTOU) Race Condition vulerability in Foscam R2C IP camera running System FW <= 1.13.1.6, and Application FW <= 2.91.2.66, allows an authenticated remote attacker with administrator permissions to execute arbitrary remote code via a malicious firmware…

  • CVE-2017-2875CriSep 19, 2018
    risk 0.59cvss 9.1epss 0.01

    An exploitable buffer overflow vulnerability exists in the Multi-Camera interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. A specially crafted request on port 10000 can cause a buffer overflow resulting in overwriting arbitrary data.

  • CVE-2017-2849HigJun 29, 2017
    risk 0.58cvss 8.8epss 0.05

    In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during NTP server configuration resulting in command injection. An attacker can simply…

  • CVE-2017-2848HigJun 29, 2017
    risk 0.58cvss 8.8epss 0.05

    In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during manual network configuration resulting in command injection. An attacker can…

  • CVE-2017-2847HigJun 29, 2017
    risk 0.58cvss 8.8epss 0.05

    In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during manual network configuration resulting in command injection. An attacker can…

  • CVE-2017-2846HigJun 29, 2017
    risk 0.58cvss 8.8epss 0.05

    In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during manual network configuration resulting in command injection. An attacker can…