Foscam IP camera 11.37.2.49 and other versions, when using the Foscam DynDNS option, generates credentials based on predictable camera subdomain names, which allows remote attackers to spoof or hijack arbitrary cameras and conduct other attacks by modifying arbitrary camera records in the Foscam DNS server.
📦
ip_camera_firmware
Vendor: maygion
Actively Exploited
0
CISA KEV List
PoC / Exploits
3
Code Available
Total RCEs
0
Remote Access
Total CVEs
8
Total Indexed
Avg. EPSS
9.11%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
10.0
CVSS
CVE-2014-1849
Exploit Found
Severity: HIGH
7.5
CVSS
CVE-2013-1605
Exploit Found
Buffer overflow in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers to execute arbitrary code via a long filename in a GET request.
Severity: HIGH
5.0
CVSS
CVE-2013-1604
Exploit Found
Directory traversal vulnerability in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers to read arbitrary files via a .. (dot dot) in the default URI.
Severity: MEDIUM