Vulnerabilities
Vulnerable Software
Foscam:  Security Vulnerabilities
Foscam IP camera 11.37.2.49 and other versions, when using the Foscam DynDNS option, generates credentials based on predictable camera subdomain names, which allows remote attackers to spoof or hijack arbitrary cameras and conduct other attacks by modifying arbitrary camera records in the Foscam DNS server.
CVSS Score
10.0
EPSS Score
0.243
Published
2014-05-14
The Foscam FI8910W camera with firmware before 11.37.2.55 allows remote attackers to obtain sensitive video and image data via a blank username and password.
CVSS Score
7.8
EPSS Score
0.003
Published
2014-03-06
Cross-site scripting (XSS) vulnerability in the web interface "WiFi scan" option in FOSCAM Wireless IP Cameras allows remote attackers to inject arbitrary web script or HTML via the SSID.
CVSS Score
4.3
EPSS Score
0.003
Published
2013-11-20
Directory traversal vulnerability in the web interface on Foscam devices with firmware before 11.37.2.49 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI, as demonstrated by discovering (1) web credentials or (2) Wi-Fi credentials.
CVSS Score
7.8
EPSS Score
0.09
Published
2013-03-15
The web interface on (1) Foscam and (2) Wansview IP cameras allows remote attackers to bypass authentication, and perform administrative functions or read the admin password, via a direct request to an unspecified URL.
CVSS Score
10.0
EPSS Score
0.031
Published
2012-12-21


Contact Us

Shodan ® - All rights reserved