VULNERABILITY INTELLIGENCE

CVE-2018-19081

CVSS score9.8 CRITICAL
EPSS probability4.97%
CISA KEVNot currently listed
Published2018-11-07
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SetDNS method allows remote attackers to execute arbitrary OS commands via the IPv4Address field.

Weakness classification

  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Primary references