PT-2022-19204 · Foscam · Foscam R2C Ip Camera
Sam Quinn
·
Published
2022-04-21
·
Updated
2022-05-04
·
CVE-2022-28743
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Foscam R2C IP camera versions System FW <= 1.13.1.6, and Application FW <= 2.91.2.66
Description
A Time-of-check Time-of-use (TOCTOU) Race Condition issue allows an authenticated remote attacker with administrator permissions to execute arbitrary remote code via a malicious firmware patch. This could grant the attacker full remote access to the IP camera and the underlying Linux system with root permissions, enabling them to change the code, add backdoor access, or invade the user's privacy by accessing the live camera stream.
Recommendations
For Foscam R2C IP camera versions System FW <= 1.13.1.6, and Application FW <= 2.91.2.66, update the firmware to a version higher than System FW 1.13.1.6 and Application FW 2.91.2.66 to resolve the issue.
At the moment, there is no information about additional mitigation measures.
Fix
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Foscam R2C Ip Camera