CVE-2018-6830
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Directory traversal vulnerability in Foscam Cameras C1 Lite V3, and C1 V3 with firmware 2.82.2.33 and earlier, FI9800P V3, FI9803P V4, FI9851P V3, and FI9853EP V2 2.84.2.33 and earlier, FI9816P V3, FI9821EP V2, FI9821P V3, FI9826P V3, and FI9831P V3 2.81.2.33 and earlier, C1, C1 V2, C1 Lite, and C1 Lite V2 2.52.2.47 and earlier, FI9800P, FI9800P V2, FI9803P V2, FI9803P V3, and FI9851P V2 2.54.2.47 and earlier, FI9815P, FI9815P V2, FI9816P, and FI9816P V2, 2.51.2.47 and earlier, R2 and R4 2.71.1.59 and earlier, C2 and FI9961EP 2.72.1.59 and earlier, FI9900EP, FI9900P, and FI9901EP 2.74.1.59 and earlier, FI9928P 2.74.1.58 and earlier, FI9803EP and FI9853EP 2.22.2.31 and earlier, FI9803P and FI9851P 2.24.2.31 and earlier, FI9821P V2, FI9826P V2, FI9831P V2, and FI9821EP 2.21.2.31 and earlier, FI9821W V2, FI9831W, FI9826W, FI9821P, FI9831P, and FI9826P 2.11.1.120 and earlier, FI9818W V2 2.13.2.120 and earlier, FI9805W, FI9804W, FI9804P, FI9805E, and FI9805P 2.14.1.120 and earlier, FI9828P, and FI9828W 2.13.1.120 and earlier, and FI9828P V2 2.11.1.133 and earlier allows remote attackers to delete arbitrary files via a .. (dot dot) in the URI path component.
Affected (45)
Products: Foscam: C1 Lite Firmware, C1 Firmware, Fi9800p Firmware, Fi9821ep Firmware, Fi9821p Firmware, Fi9826p Firmware, Fi9831p Firmware, Fi9803p Firmware, Fi9851p Firmware, Fi9815p Firmware, Fi9816p Firmware, R2 Firmware, R4 Firmware, C2 Firmware, Fi9961ep Firmware, Fi9900ep Firmware, Fi9900p Firmware, Fi9901ep Firmware, Fi9928p Firmware, Fi9803ep Firmware, Fi9853ep Firmware, Fi9821w Firmware, Fi9831w Firmware, Fi9826w Firmware, Fi9818w Firmware, Fi9805w Firmware, Fi9804w Firmware, Fi9804p Firmware, Fi9805e Firmware, Fi9805p Firmware, Fi9828p Firmware, Fi9828w Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.82.2.33 |
| Running on/with | Platform Versions |
|---|---|
Foscam C1 Lite | Version 3 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.82.2.33 |
| Running on/with | Platform Versions |
|---|---|
Foscam C1 | Version 3 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.81.2.33 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9800p | Version 3 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.81.2.33 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9821ep | Version 2 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.81.2.33 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9821p | Version 3 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.81.2.33 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9826p | Version 3 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.81.2.33 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9831p | Version 3 |
Configuration H
| Running on/with | Platform Versions |
|---|---|
Foscam C1 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.52.2.47 |
| Running on/with | Platform Versions |
|---|---|
Foscam C1 | Version 2 |
Configuration J
| Running on/with | Platform Versions |
|---|---|
Foscam C1 Lite | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.52.2.47 |
| Running on/with | Platform Versions |
|---|---|
Foscam C1 Lite | Version 2 |
Configuration L
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9800p | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.54.2.47 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9800p | Version 2 |
Configuration N
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9803p | Version 2 |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.54.2.47 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9803p | Version 3 |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.54.2.47 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9851p | Version 2 |
Configuration Q
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9815p | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.51.2.47 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9815p | Version 2 |
Configuration S
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9816p | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.51.2.47 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9816p | Version 2 |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.71.1.59 |
| Running on/with | Platform Versions |
|---|---|
Foscam R2 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.71.1.59 |
| Running on/with | Platform Versions |
|---|---|
Foscam R4 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.72.1.59 |
| Running on/with | Platform Versions |
|---|---|
Foscam C2 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.72.1.59 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9961ep | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.74.1.59 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9900ep | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.74.1.59 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9900p | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.74.1.59 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9901ep | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.74.1.58 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9928p | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.22.2.31 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9803ep | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.22.2.31 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9853ep | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.24.2.31 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9803p | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.24.2.31 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9851p | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.21.2.31 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9821p | Version 2 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.21.2.31 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9826p | Version 2 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.21.2.31 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9831p | Version 2 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.21.2.31 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9821ep | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.11.1.120 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9821w | Version 2 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.11.1.120 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9831w | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.11.1.120 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9826w | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.11.1.120 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9821p | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.11.1.120 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9831p | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.11.1.120 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9826p | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.13.2.120 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9818w | Version 2 |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.14.1.120 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9805w | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.14.1.120 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9804w | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.14.1.120 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9804p | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.14.1.120 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9805e | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.14.1.120 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9805p | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.13.1.120 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9828p | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.13.1.120 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9828w | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.11.1.133 |
| Running on/with | Platform Versions |
|---|---|
Foscam Fi9828p | Version 2 |
References (4)
Source: cve@mitre.org
ExploitThird Party Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.