CVE-2012-3002
CVE-2012-3002 is a critical-severity vulnerability in Foscam H.264 Hi3510/11/12 Ip Camera with a CVSS 2.0 base score of 10.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-287.
Key facts
- Severity: Critical (CVSS 2.0 base score 10.0)
- EPSS exploit prediction: 4% (89th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-287
- Affected product: Foscam H.264 Hi3510/11/12 Ip Camera
- Published:
- Last modified:
Description
The web interface on (1) Foscam and (2) Wansview IP cameras allows remote attackers to bypass authentication, and perform administrative functions or read the admin password, via a direct request to an unspecified URL.
Frequently asked questions
- What is CVE-2012-3002?
- The web interface on (1) Foscam and (2) Wansview IP cameras allows remote attackers to bypass authentication, and perform administrative functions or read the admin password, via a direct request to an unspecified URL.
- How severe is CVE-2012-3002?
- CVE-2012-3002 has a CVSS 2.0 base score of 10.0, rated critical severity.
- Is CVE-2012-3002 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 4% (89th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2012-3002?
- CVE-2012-3002 primarily affects Foscam H.264 Hi3510/11/12 Ip Camera. In total, 2 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2012-3002?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2012-3002 published?
- CVE-2012-3002 was published on 2012-12-21 and last updated on 2026-06-16.
References
- http://foscam.us/forum/h264-ip-camera-web-interface-authentication-bypass-test-tool-t3252.html
- http://secunia.com/advisories/50950
- http://secunia.com/advisories/50966
- http://www.foscam.com/help.aspx?TypeId=11
- http://www.kb.cert.org/vuls/id/265532
- http://www.securityfocus.com/bid/55873
Affected products (2)
- cpe:2.3:h:foscam:h.264_hi3510\/11\/12_ip_camera:-:*:*:*:*:*:*:*
- cpe:2.3:h:wansview:h.264_hi3510\/11\/12_ip_camera:-:*:*:*:*:*:*:*
Other CWE-287 (Improper Authentication) vulnerabilities
- CVE-2026-94493 — Critical (CVSS 10.0): A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of…
- CVE-2026-83099 — Critical (CVSS 10.0): Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).…
- CVE-2026-83059 — Critical (CVSS 10.0): Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server).…
- CVE-2026-83021 — Critical (CVSS 10.0): Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported…
- CVE-2026-83020 — Critical (CVSS 10.0): Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized…
- CVE-2026-71133 — Critical (CVSS 10.0): Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).…
Browse all CWE-287 (Improper Authentication) vulnerabilities →