First published: Wed Nov 07 2018(Updated: )
An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The CGIProxy.fcgi?cmd=setTelnetSwitch feature is authorized for hidden factory credentials.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opticam I5 Application Firmware | =2.21.1.128 | |
Opticam I5 System Firmware | =1.5.2.11 | |
Opticam i5 | ||
Foscam C2 Application Firmware | =2.72.1.32 | |
Foscam C2 System Firmware | =1.11.1.8 | |
Foscam C2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19068 is a vulnerability discovered on Foscam Opticam i5 devices that allows unauthorized access to hidden factory credentials.
Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128 are affected by CVE-2018-19068.
The severity of CVE-2018-19068 is medium, with a severity value of 4.9.
To fix the CVE-2018-19068 vulnerability, it is recommended to update the System Firmware to version 1.5.2.12 or higher and the Application Firmware to version 2.21.1.129 or higher.
You can find more information about CVE-2018-19068 at the following reference link: https://sintonen.fi/advisories/foscam-ip-camera-multiple-vulnerabilities.txt