CVE-2018-19074 describes a critical firewall bypass vulnerability affecting Foscam C2 and Opticam i5 devices, specifically with certain system and application firmware versions. The flaw allows attackers to bypass the firewall, which only blocks port 443 and partially port 88, enabling unauthorized access to the device. Rated with a CVSS score of 7.5 (HIGH), this vulnerability is easily exploitable over the network with low complexity and no user interaction, potentially leading to high integrity impact. While there is no known active exploitation, public exploit code, or significant community discussion, the ease of exploitation makes it a notable risk for affected devices.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.21.1.128CPE matchmatch criteria | cpe:2.3:o:opticam:i5_application_firmware:2.21.1.128:*:*:*:*:*:*:* | ||
1.5.2.11CPE matchmatch criteria | cpe:2.3:o:opticam:i5_system_firmware:1.5.2.11:*:*:*:*:*:*:* | ||
2.72.1.32CPE matchmatch criteria | cpe:2.3:o:foscam:c2_application_firmware:2.72.1.32:*:*:*:*:*:*:* | ||
1.11.1.8CPE matchmatch criteria | cpe:2.3:o:foscam:c2_system_firmware:1.11.1.8:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.