CVE-2014-1849
Title: Foscam Ip Camera Firmware
Other
Proof Of Concept
PoC Available for CVE-2014-1849
CWE Category
CWE-255
Published Date
May 14, 2014
Modified Date
Jun 17, 2026
Exploit Status
Available
Score
10.0
CVSS v2.0
Exploit Probability (EPSS)
12.09%
Vulnerability Summary
CVE-2014-1849: Foscam IP camera 11.37.2.49 and other versions, when using the Foscam DynDNS option, generates credentials based on predictable camera subdomain names, which allows remote attackers to spoof or hijack arbitrary cameras and conduct other attacks by modifying arbitrary camera records in the Foscam DNS server.
Impacted Vendors
Reference Links
http://blog.shekyan.com/2014/05/cve-2014-1849-foscam-dynamic-dns-predictable-credentials-vulnerability.html
http://seclists.org/fulldisclosure/2014/May/35
https://github.com/artemharutyunyan/getmecamtool/blob/master/src/dnsmod.c
http://blog.shekyan.com/2014/05/cve-2014-1849-foscam-dynamic-dns-predictable-credentials-vulnerability.html
http://seclists.org/fulldisclosure/2014/May/35
https://github.com/artemharutyunyan/getmecamtool/blob/master/src/dnsmod.c
CVSS v2.0
Source Entity
[email protected]
Severity
HIGH
10.0
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:N/AC:L/Au:N/C:C/I:C/A:C
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2014-1849 Exploits & PoCs (Proof Of Concept)
Exploit-DB
https://www.exploit-db.com/exploits/39195
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
N/A
Complexity
N/A
Privileges
N/A
Interaction
NONE
CVSS Vector String
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected Stack
No specific products linked.