CVE-2018-19070
7.2
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD
Description
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. They allow remote attackers to execute arbitrary OS commands via shell metacharacters in the usrName parameter of a CGIProxy.fcgi addAccount action.
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.21.1.128 | |
| Version 1.5.2.11 |
| Running on/with | Platform Versions |
|---|---|
Opticam I5 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.72.1.32 | |
| Version 1.11.1.8 |
| Running on/with | Platform Versions |
|---|---|
Foscam C2 | All versions |
References (2)
Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.