peter bassill · operator
$ cve CVE-2017-2805 JSON

CVE-2017-2805

9.8
CRITICAL · CVSS 3.1 · EPSS 26.2% (pctl 98)

Patch early

EPSS 26.2% — above the 10% action threshold.

Description

An exploitable stack-based buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera. A specially crafted http request can cause a stack-based buffer overflow resulting in overwriting arbitrary data on the stack frame. An attacker can simply send an http request to the device to trigger this vulnerability.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS26.25% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-787
On CISA KEVno
Public exploitnone known
Published2017-06-21
Last modified2026-06-17

Affected (2)

VendorProduct
foscamc1 hd indoor camera
foscamc1 hd indoor camera firmware

References

→ the Explorer  ·  watch your stack  ·  NVD