Directory traversal vulnerability in Foscam Cameras C1 Lite V3, and C1 V3 with firmware 2.82.2.33 and earlier, FI9800P V3, FI9803P V4, FI9851P V3, and FI9853EP V2 2.84.2.33 and earlier, FI9816P V3, FI9821EP V2, FI9821P V3, FI9826P V3, and FI9831P V3 2.81.2.33 and earlier, C1, C1 V2, C1 Lite, and C1 Lite V2 2.52.2.47 and earlier, FI9800P, FI9800P V2, FI9803P V2, FI9803P V3, and FI9851P V2 2.54.2.47 and earlier, FI9815P, FI9815P V2, FI9816P, and FI9816P V2, 2.51.2.47 and earlier, R2 and R4 2.71.1.59 and earlier, C2 and FI9961EP 2.72.1.59 and earlier, FI9900EP, FI9900P, and FI9901EP 2.74.1.59 and earlier, FI9928P 2.74.1.58 and earlier, FI9803EP and FI9853EP 2.22.2.31 and earlier, FI9803P and FI9851P 2.24.2.31 and earlier, FI9821P V2, FI9826P V2, FI9831P V2, and FI9821EP 2.21.2.31 and earlier, FI9821W V2, FI9831W, FI9826W, FI9821P, FI9831P, and FI9826P 2.11.1.120 and earlier, FI9818W V2 2.13.2.120 and earlier, FI9805W, FI9804W, FI9804P, FI9805E, and FI9805P 2.14.1.120 and earlier, FI9828P, and FI9828W 2.13.1.120 and earlier, and FI9828P V2 2.11.1.133 and earlier allows remote attackers to delete arbitrary files via a .
Published Jul 9, 2018
7.5
HIGHCVSS 3.0
EPSS 2.63%
Description
Directory traversal vulnerability in Foscam Cameras C1 Lite V3, and C1 V3 with firmware 2.82.2.33 and earlier, FI9800P V3, FI9803P V4, FI9851P V3, and FI9853EP V2 2.84.2.33 and earlier, FI9816P V3, FI9821EP V2, FI9821P V3, FI9826P V3, and FI9831P V3 2.81.2.33 and earlier, C1, C1 V2, C1 Lite, and C1 Lite V2 2.52.2.47 and earlier, FI9800P, FI9800P V2, FI9803P V2, FI9803P V3, and FI9851P V2 2.54.2.47 and earlier, FI9815P, FI9815P V2, FI9816P, and FI9816P V2, 2.51.2.47 and earlier, R2 and R4 2.71.1.59 and earlier, C2 and FI9961EP 2.72.1.59 and earlier, FI9900EP, FI9900P, and FI9901EP 2.74.1.59 and earlier, FI9928P 2.74.1.58 and earlier, FI9803EP and FI9853EP 2.22.2.31 and earlier, FI9803P and FI9851P 2.24.2.31 and earlier, FI9821P V2, FI9826P V2, FI9831P V2, and FI9821EP 2.21.2.31 and earlier, FI9821W V2, FI9831W, FI9826W, FI9821P, FI9831P, and FI9826P 2.11.1.120 and earlier, FI9818W V2 2.13.2.120 and earlier, FI9805W, FI9804W, FI9804P, FI9805E, and FI9805P 2.14.1.120 and earlier, FI9828P, and FI9828W 2.13.1.120 and earlier, and FI9828P V2 2.11.1.133 and earlier allows remote attackers to delete arbitrary files via a .. (dot dot) in the URI path component.
Affected products
No data.
Configuration 1
- ≤ 2.82.2.33
Configuration 2
- ≤ 2.82.2.33
Configuration 3
- ≤ 2.81.2.33
Configuration 4
- ≤ 2.81.2.33
Configuration 5
- ≤ 2.81.2.33
Configuration 6
- ≤ 2.81.2.33
Configuration 7
- ≤ 2.81.2.33
Configuration 8
- ≤ 2.52.2.47
Configuration 9
- ≤ 2.52.2.47
Configuration 10
- ≤ 2.52.2.47
Configuration 11
- ≤ 2.52.2.47
Configuration 12
- ≤ 2.54.2.47
Configuration 13
- ≤ 2.54.2.47
Configuration 14
- ≤ 2.54.2.47
Configuration 15
- ≤ 2.54.2.47
Configuration 16
- ≤ 2.54.2.47
Configuration 17
- ≤ 2.51.2.47
Configuration 18
- ≤ 2.51.2.47
Configuration 19
- ≤ 2.51.2.47
Configuration 20
- ≤ 2.51.2.47
Configuration 21
- ≤ 2.71.1.59
Configuration 22
- ≤ 2.71.1.59
Configuration 23
- ≤ 2.72.1.59
Configuration 24
- ≤ 2.72.1.59
Configuration 25
- ≤ 2.74.1.59
Configuration 26
- ≤ 2.74.1.59
Configuration 27
- ≤ 2.74.1.59
Configuration 28
- ≤ 2.74.1.58
Configuration 29
- ≤ 2.22.2.31
Configuration 30
- ≤ 2.22.2.31
Configuration 31
- ≤ 2.24.2.31
Configuration 32
- ≤ 2.24.2.31
Configuration 33
- ≤ 2.21.2.31
Configuration 34
- ≤ 2.21.2.31
Configuration 35
- ≤ 2.21.2.31
Configuration 36
- ≤ 2.21.2.31
Configuration 37
- ≤ 2.11.1.120
Configuration 38
- ≤ 2.11.1.120
Configuration 39
- ≤ 2.11.1.120
Configuration 40
- ≤ 2.11.1.120
Configuration 41
- ≤ 2.11.1.120
Configuration 42
- ≤ 2.11.1.120
Configuration 43
- ≤ 2.13.2.120
Configuration 44
- ≤ 2.14.1.120
Configuration 45
- ≤ 2.14.1.120
Configuration 46
- ≤ 2.14.1.120
Configuration 47
- ≤ 2.14.1.120
Configuration 48
- ≤ 2.14.1.120
Configuration 49
- ≤ 2.13.1.120
Configuration 50
- ≤ 2.13.1.120
Configuration 51
- ≤ 2.11.1.133
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
AV:N/AC:L/Au:N/C:N/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.63% (0.02632) | 85.00th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.63% (0.02632) | 83.50th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.25% (0.00247) | 65.10th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.24% (0.00244) | 63.43th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.24% (0.00244) | 60.45th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.05% (0.01055) | 52.13th | v2 (v2022.01.01) |
| Sep 17, 2022 | 1.05% (0.01055) | 50.47th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.05% (0.01055) | 48.43th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.05% (0.01055) | 27.52th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.78% (0.00785) | 22.12th | v1 |
| Jan 6, 2022 | 0.78% (0.00785) | 21.52th | v1 |
| Sep 1, 2021 | 0.78% (0.00785) | 52.07th | v1 |
| Apr 14, 2021 | 0.78% (0.00785) | 0.00th | v1 |
References (2)
- https://blog.vdoo.com/2018/06/06/vdoo-has-found-major-vulnerabilities-in-foscam-cameras/ x_refsource_MISCExploitThird Party Advisory
- https://www.foscam.com/company/securing-your-foscam-camera-important-notice.html x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://blog.vdoo.com/2018/06/06/vdoo-has-found-major-vulnerabilities-in-foscam-cameras/ | x_refsource_MISCExploitThird Party Advisory | |
| https://www.foscam.com/company/securing-your-foscam-camera-important-notice.html | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.