Vulnerability Description
Hard-coded FTP credentials (r:r) are included in the Foscam C1 running firmware 1.9.1.12. Knowledge of these credentials would allow remote access to any cameras found on the internet that do not have port 50021 blocked by an intermediate device.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Foscam | C1 Webcam Firmware | 1.9.1.12 |
| Foscam | C1 Webcam | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/99193Broken LinkThird Party AdvisoryVDB Entry
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2016-0245Third Party Advisory
- http://www.securityfocus.com/bid/99193Broken LinkThird Party AdvisoryVDB Entry
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2016-0245Third Party Advisory
FAQ
What is CVE-2016-8731?
CVE-2016-8731 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Hard-coded FTP credentials (r:r) are included in the Foscam C1 running firmware 1.9.1.12. Knowledge of these credentials would allow remote access to any cameras found on the internet that do not have...
How severe is CVE-2016-8731?
CVE-2016-8731 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-8731?
Check the references section above for vendor advisories and patch information. Affected products include: Foscam C1 Webcam Firmware, Foscam C1 Webcam.