VULNERABILITY INTELLIGENCE
CVE-2018-19081
CVSS score9.8 CRITICAL
EPSS probability4.97%
CISA KEVNot currently listed
Published2018-11-07
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SetDNS method allows remote attackers to execute arbitrary OS commands via the IPv4Address field.
Weakness classification
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Primary references
- cve@mitre.org — Exploit, Third Party Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Exploit, Third Party Advisory