First published: Wed Nov 07 2018(Updated: )
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ftpuser1 account has a blank password, which cannot be changed.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opticam I5 Application Firmware | =2.21.1.128 | |
Opticam I5 System Firmware | =1.5.2.11 | |
Opticam i5 | ||
Foscam C2 System Firmware | =2.72.1.32 | |
Foscam C2 Firmware | =1.11.1.8 | |
Foscam C2 System Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19064 is classified as a critical vulnerability due to the presence of a default blank password for an account.
To fix CVE-2018-19064, it is recommended to update the firmware of affected Foscam C2 and Opticam i5 devices to the latest version.
CVE-2018-19064 affects Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, as well as Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128.
Using the affected devices without addressing CVE-2018-19064 poses a significant security risk, as unauthorized access is possible due to the default blank password.
No, the ftpuser1 account in CVE-2018-19064 has a blank password that cannot be changed, making it vulnerable.