First published: Thu Jun 29 2017(Updated: )
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during manual network configuration resulting in command injection. An attacker can simply send an HTTP request to the device to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Foscam IP Camera Firmware | =2.52.2.37 | |
Foscam C1 HD Indoor Camera |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-2846 is assessed as high due to its potential for command injection.
To fix CVE-2017-2846, apply the latest firmware update provided by Foscam for the C1 Indoor HD camera.
CVE-2017-2846 is classified as a command injection vulnerability.
Users of Foscam C1 Indoor HD cameras with firmware version 2.52.2.37 are affected by CVE-2017-2846.
An attacker can perform arbitrary command execution on vulnerable devices through specially crafted HTTP requests.