CVE-2017-2844
CVE-2017-2844 is a high-severity vulnerability in Foscam C1 Indoor Hd Camera Firmware with a CVSS 3.x base score of 8.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-78.
Key facts
- Severity: High (CVSS 3.x base score 8.8)
- CVSS v2: 6.5
- EPSS exploit prediction: 3% (89th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-78
- Affected product: Foscam C1 Indoor Hd Camera Firmware
- Published:
- Last modified:
Description
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An attacker can simply send an HTTP request to the device to trigger this vulnerability.
Frequently asked questions
- What is CVE-2017-2844?
- In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An attacker can simply send an HTTP request to the device to trigger this vulnerability.
- How severe is CVE-2017-2844?
- CVE-2017-2844 has a CVSS 3.x base score of 8.8, rated high severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2017-2844 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 3% (89th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2017-2844?
- CVE-2017-2844 affects Foscam C1 Indoor Hd Camera Firmware. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2017-2844?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2017-2844 published?
- CVE-2017-2844 was published on 2017-06-29 and last updated on 2026-06-17.
References
- http://www.securityfocus.com/bid/99184
- https://talosintelligence.com/vulnerability_reports/TALOS-2017-0346
Affected products (1)
- cpe:2.3:o:foscam:c1_indoor_hd_camera_firmware:2.52.2.37:*:*:*:*:*:*:*
More vulnerabilities in Foscam C1 Indoor Hd Camera Firmware
- CVE-2017-2850 — High (CVSS 8.8): In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted…
- CVE-2017-2849 — High (CVSS 8.8): In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted…
- CVE-2017-2848 — High (CVSS 8.8): In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted…
- CVE-2017-2847 — High (CVSS 8.8): In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted…
- CVE-2017-2846 — High (CVSS 8.8): In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted…
- CVE-2017-2845 — High (CVSS 8.8): An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD…
All CVEs affecting Foscam C1 Indoor Hd Camera Firmware →
Other CWE-78 (OS Command Injection) vulnerabilities
- CVE-2026-100382 — Critical (CVSS 10.0): Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia…
- CVE-2026-77521 — Critical (CVSS 10.0): MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool,…
- CVE-2026-82004 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS…
- CVE-2026-76197 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS…
- CVE-2026-76195 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS…
- CVE-2026-19188 — Critical (CVSS 10.0): A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The…