Vstarcam develops a narrow range of network-connected camera and surveillance products, including models such as the C7824IWP, which present a focused but security-sensitive attack surface given their direct internet exposure. The durable vulnerability signal centers on input-handling and authentication weaknesses, including improper input validation and missing authentication controls on critical functions, which are characteristic of IoT device firmware. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vstarcam over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12288CRITICAL An issue was discovered in upgrade_htmls.cgi on VStarcam 100T (C7824WIP) KR75.8.53.20 and 200V (C38S) KR203.18.1.20 devices. The web service, network, and account files can be mani | May 23, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-11014CRITICAL The VStarCam vstc.vscam.client library and vstc.vscam shared object, as used in the Eye4 application (for Android, iOS, and Windows), do not prevent spoofing of the camera server. | Apr 8, 2019 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vstarcam.
Media articles that mention a CVE ID that affects a product developed by Vstarcam — matched by CVE ID, not by vendor name.