An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary shell characters during account creation resulting in command injection. An attacker can simply send an HTTP request to the device to trigger this vulnerability.
                
            Metrics
Affected Vendors & Products
References
        History
                    No history.
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: talos
Published: 2017-06-21T13:00:00
Updated: 2024-08-05T14:09:16.355Z
Reserved: 2016-12-01T00:00:00
Link: CVE-2017-2827
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Deferred
Published: 2017-06-21T13:29:00.253
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-2827
 Redhat
                        Redhat
                    No data.