opticam CVE Vulnerabilities & Metrics

Focus on opticam vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About opticam Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with opticam. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total opticam CVEs: 20
Earliest CVE date: 07 Nov 2018, 18:29 UTC
Latest CVE date: 07 Nov 2018, 18:29 UTC

Latest CVE reference: CVE-2018-19082

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical opticam CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 6.88

Max CVSS: 10.0

Critical CVEs (≥9): 7

CVSS Range vs. Count

Range Count
0.0-3.9 1
4.0-6.9 9
7.0-8.9 3
9.0-10.0 7

CVSS Distribution Chart

Top 5 Highest CVSS opticam CVEs

These are the five CVEs with the highest CVSS scores for opticam, sorted by severity first and recency.

All CVEs for opticam

CVE-2018-19082 opticam vulnerability CVSS: 7.5 07 Nov 2018, 18:29 UTC

An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SetDNS method allows remote attackers to conduct stack-based buffer overflow attacks via the IPv4Address field.

CVE-2018-19081 opticam vulnerability CVSS: 10.0 07 Nov 2018, 18:29 UTC

An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SetDNS method allows remote attackers to execute arbitrary OS commands via the IPv4Address field.

CVE-2018-19080 opticam vulnerability CVSS: 4.3 07 Nov 2018, 18:29 UTC

An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SetHostname method allows unauthenticated persistent XSS.

CVE-2018-19079 opticam vulnerability CVSS: 7.8 07 Nov 2018, 18:29 UTC

An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SystemReboot method allows unauthenticated reboot.

CVE-2018-19078 opticam vulnerability CVSS: 5.0 07 Nov 2018, 18:29 UTC

An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The response to an ONVIF media GetStreamUri request contains the administrator username and password.

CVE-2018-19077 opticam vulnerability CVSS: 7.8 07 Nov 2018, 18:29 UTC

An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. RtspServer allows remote attackers to cause a denial of service (daemon hang or restart) via a negative integer in the RTSP Content-Length header.

CVE-2018-19076 opticam vulnerability CVSS: 5.0 07 Nov 2018, 18:29 UTC

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The FTP and RTSP services make it easier for attackers to conduct brute-force authentication attacks, because failed-authentication limits apply only to HTTP (not FTP or RTSP).

CVE-2018-19075 opticam vulnerability CVSS: 5.0 07 Nov 2018, 18:29 UTC

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The firewall feature makes it easier for remote attackers to ascertain credentials and firewall rules because invalid credentials lead to error -2, whereas rule-based blocking leads to error -8.

CVE-2018-19074 opticam vulnerability CVSS: 5.0 07 Nov 2018, 18:29 UTC

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The firewall has no effect except for blocking port 443 and partially blocking port 88.

CVE-2018-19073 opticam vulnerability CVSS: 9.0 07 Nov 2018, 18:29 UTC

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. They allow attackers to execute arbitrary OS commands via shell metacharacters in the modelName, by leveraging /mnt/mtd/app/config/ProductConfig.xml write access.

CVE-2018-19072 opticam vulnerability CVSS: 3.6 07 Nov 2018, 18:29 UTC

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. /mnt/mtd/app has 0777 permissions, allowing local users to replace an archive file (within that directory) to control what is extracted to RAM at boot time.

CVE-2018-19071 opticam vulnerability CVSS: 4.6 07 Nov 2018, 18:29 UTC

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. /mnt/mtd/boot.sh has 0777 permissions, allowing local users to control the commands executed at system start-up.

CVE-2018-19070 opticam vulnerability CVSS: 9.0 07 Nov 2018, 18:29 UTC

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. They allow remote attackers to execute arbitrary OS commands via shell metacharacters in the usrName parameter of a CGIProxy.fcgi addAccount action.

CVE-2018-19069 opticam vulnerability CVSS: 10.0 07 Nov 2018, 18:29 UTC

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The CGIProxy.fcgi?cmd=setTelnetSwitch feature is authorized for the root user with a password of toor.

CVE-2018-19068 opticam vulnerability CVSS: 4.0 07 Nov 2018, 18:29 UTC

An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The CGIProxy.fcgi?cmd=setTelnetSwitch feature is authorized for hidden factory credentials.

CVE-2018-19067 opticam vulnerability CVSS: 10.0 07 Nov 2018, 18:29 UTC

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. There is a hardcoded Ak47@99 password for the factory~ account.

CVE-2018-19066 opticam vulnerability CVSS: 5.0 07 Nov 2018, 18:29 UTC

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The exported device configuration is encrypted with the hardcoded Pxift* password in some cases.

CVE-2018-19065 opticam vulnerability CVSS: 5.0 07 Nov 2018, 18:29 UTC

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The exported device configuration is encrypted with the hardcoded BpP+2R9*Q password in some cases.

CVE-2018-19064 opticam vulnerability CVSS: 10.0 07 Nov 2018, 18:29 UTC

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ftpuser1 account has a blank password, which cannot be changed.

CVE-2018-19063 opticam vulnerability CVSS: 10.0 07 Nov 2018, 18:29 UTC

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The admin account has a blank password.