Arbitrary Command Execution in Foscam C1 Indoor HD Camera
CVE-2017-2842
8.8HIGH
What is CVE-2017-2842?
The Foscam C1 Indoor HD Camera is susceptible to an issue within its web management interface. By sending a specially crafted HTTP request, an attacker can inject arbitrary data into the 'msmtprc' configuration file. This injection may enable unauthorized command execution on the device, potentially leading to wider system compromise. To mitigate this risk, users are advised to implement security best practices and update to the latest firmware.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Indoor IP Camera C1 Series
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
