PT-2022-19204 · Foscam · Foscam R2C Ip Camera

Sam Quinn

·

Published

2022-04-21

·

Updated

2022-05-04

·

CVE-2022-28743

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Foscam R2C IP camera versions System FW <= 1.13.1.6, and Application FW <= 2.91.2.66
Description A Time-of-check Time-of-use (TOCTOU) Race Condition issue allows an authenticated remote attacker with administrator permissions to execute arbitrary remote code via a malicious firmware patch. This could grant the attacker full remote access to the IP camera and the underlying Linux system with root permissions, enabling them to change the code, add backdoor access, or invade the user's privacy by accessing the live camera stream.
Recommendations For Foscam R2C IP camera versions System FW <= 1.13.1.6, and Application FW <= 2.91.2.66, update the firmware to a version higher than System FW 1.13.1.6 and Application FW 2.91.2.66 to resolve the issue. At the moment, there is no information about additional mitigation measures.

Fix

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-28743

Affected Products

Foscam R2C Ip Camera