CVE-2017-2877 CRITICAL

CVE-2017-2877

Vendor Foscam
Product Foscam C1 Indoor HD Camera
Published September 19, 2018
Last update September 17, 2024

CVSS base score

9.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

A missing error check exists in the Multi-Camera interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. A specially crafted request on port 10001 could allow an attacker to reset the user accounts to factory defaults, without authentication.

Key dates

02Disclosure timeline

September 19, 2018 CVE published
September 17, 2024 Record updated