Myspotcam produces a narrow line of networked security cameras—the FHD 2 and Sense models—that exhibit a consistent pattern of command-injection and hard-coded credential vulnerabilities across their firmware implementations. These weaknesses are characteristic of embedded device design and reflect insufficient input sanitization and credential management in internet-facing appliances. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Myspotcam over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-38027CRITICAL SpotCam Co., Ltd. SpotCam Sense’s hidden Telnet function has a vulnerability of OS command injection. An remote unauthenticated attacker can exploit this vulnerability to execute c | Aug 28, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-38026CRITICAL
SpotCam Co., Ltd. SpotCam FHD 2 has a vulnerability of using hard-coded uBoot credentials. An remote attacker can exploit this vulnerability to access the system to perform arbitr | Aug 28, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-38025CRITICAL
SpotCam Co., Ltd. SpotCam FHD 2’s hidden Telnet function has a vulnerability of OS command injection. An remote unauthenticated attacker can exploit this vulnerability to execute | Aug 28, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-38024CRITICAL
SpotCam Co., Ltd. SpotCam FHD 2’s hidden Telnet function has a vulnerability of using hard-coded Telnet credentials. An remote unauthenticated attacker can exploit this vulnerabil | Aug 28, 2023 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Myspotcam.
Media articles that mention a CVE ID that affects a product developed by Myspotcam — matched by CVE ID, not by vendor name.