Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Foscam

First CVE: Dec 21, 2012Active for: 14 yearsTotal CVEs: 65
50.2
VTI Score
TOP TARGET

Foscam manufactures a well-represented line of consumer and small-business IP cameras and related firmware, from the C1 and C2 series, that are widely deployed in surveillance networks and remote-monitoring installations. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity; the exposure recurs through weakness classes including OS command injection, classic buffer overflows, hard-coded credentials, and improper authentication that are endemic to embedded camera firmware with minimal input validation and legacy authentication schemes. The firmware-centric nature of Foscam's product line means that remediation typically lags disclosure, leaving devices in the field vulnerable for extended periods and creating persistent targets for botnet recruitment and lateral-network pivoting. Defenders should inventory deployed Foscam cameras, prioritize network segmentation for camera management interfaces, and treat firmware updates as security-critical rather than optional. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
65
Total CVEs
More Total CVEs than 99% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
8.1
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Foscam over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 21, 2012
13 years ago
Most Recent CVE
Apr 21, 2022
1,555 days ago

Products(84 total)

Top CVEs

Signals from CVEs in this vendor scope (65 CVEs).

65 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-1849HIGH
Foscam IP camera 11.37.2.49 and other versions, when using the Foscam DynDNS option, generates credentials based on predictable camera subdomain names, which allows remote attacker
May 14, 201410.047NOYES
CVE-2017-2805CRITICAL
An exploitable stack-based buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera. A specially crafted http request can cause a
Jun 21, 20179.844NONO
CVE-2013-2574HIGH
An Access vulnerability exists in FOSCAM IP Camera FI8620 due to insufficient access restrictions in the /tmpfs/ and /log/ directories, which could let a malicious user obtain sens
Jan 29, 20207.543NOYES
CVE-2018-19081CRITICAL
An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SetDNS method allows remote attackers t
Nov 7, 20189.833NONO
CVE-2013-2560HIGH
Directory traversal vulnerability in the web interface on Foscam devices with firmware before 11.37.2.49 allows remote attackers to read arbitrary files via a .. (dot dot) in the U
Mar 15, 20137.833NOYES
CVE-2021-43517CRITICAL
FOSCAM Camera FI9805E with firmware V4.02.R12.00018510.10012.143900.00000 contains a backdoor that opens Telnet port when special command is sent on port 9530.
Apr 8, 20229.830NONO
CVE-2018-19082CRITICAL
An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SetDNS method allows remote attackers t
Nov 7, 20189.830NONO
CVE-2018-19078CRITICAL
An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The response to an ONVIF media GetStreamUri request contains
Nov 7, 20189.830NONO
CVE-2018-19067CRITICAL
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application
Nov 7, 20189.830NONO
CVE-2018-19064CRITICAL
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application
Nov 7, 20189.830NONO
View all 65 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products65 CVEs
12%
68%
20%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (3.1%)
Network56 (86.2%)
Unknown5 (7.7%)
Physical0 (0.0%)
Adjacent Network2 (3.1%)
Attack Complexity
Low52 (80.0%)
High8 (12.3%)
Unknown5 (7.7%)
User Interaction
None59 (90.8%)
Unknown5 (7.7%)
Required1 (1.5%)
Privileges Required
Low16 (24.6%)
High9 (13.8%)
None35 (53.8%)
Unknown5 (7.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (65 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
4.6% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Foscam.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Foscam — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Foscam's Products

View all 3 CNAs →

Top CWEs