CVE-2018-19081
9.8
CRITICAL · CVSS 3.0 · EPSS 5% (pctl 92)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SetDNS method allows remote attackers to execute arbitrary OS commands via the IPv4Address field.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.97% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-11-07 |
| Last modified | 2026-06-17 |
Affected (6)
| Vendor | Product |
|---|---|
| foscam | c2 |
| foscam | c2 application firmware |
| foscam | c2 system firmware |
| opticam | i5 |
| opticam | i5 application firmware |
| opticam | i5 system firmware |
References
→ the Explorer · watch your stack · NVD