CRITICAL · 9.8

CVE-2016-8731

Hard-coded FTP credentials (r:r) are included in the Foscam C1 running firmware 1.9.1.12. Knowledge of these credentials would allow remote access to any cameras found on the internet that do not have...

Vulnerability Description

Hard-coded FTP credentials (r:r) are included in the Foscam C1 running firmware 1.9.1.12. Knowledge of these credentials would allow remote access to any cameras found on the internet that do not have port 50021 blocked by an intermediate device.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
FoscamC1 Webcam Firmware1.9.1.12
FoscamC1 Webcam-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-8731?

CVE-2016-8731 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Hard-coded FTP credentials (r:r) are included in the Foscam C1 running firmware 1.9.1.12. Knowledge of these credentials would allow remote access to any cameras found on the internet that do not have...

How severe is CVE-2016-8731?

CVE-2016-8731 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2016-8731?

Check the references section above for vendor advisories and patch information. Affected products include: Foscam C1 Webcam Firmware, Foscam C1 Webcam.