PT-2018-14781 · Foscam · Foscam Opticam I5

Published

2018-11-07

·

Updated

2019-10-03

·

CVE-2018-19068

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128
Description An issue was discovered where the CGIProxy.fcgi?cmd=setTelnetSwitch feature is authorized for hidden factory credentials. This affects the ability to secure the device properly, as unauthorized access could be gained through the use of these hidden credentials.
Recommendations For Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128, consider disabling the CGIProxy.fcgi feature until a patch is available to prevent unauthorized access using the hidden factory credentials.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-19068

Affected Products

Foscam Opticam I5