PT-2017-9770 · Foscam · Foscam C1

Published

2017-06-21

·

Updated

2022-12-14

·

CVE-2016-8731

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Foscam C1 version 1.9.1.12
Description The issue concerns hard-coded FTP credentials, specifically r:r, included in the firmware. This could allow remote access to cameras connected to the internet without port 50021 blocked by an intermediate device.
Recommendations For Foscam C1 version 1.9.1.12, consider blocking port 50021 to prevent unauthorized access until a firmware update is available that removes the hard-coded credentials.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-8731

Affected Products

Foscam C1