An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. /mnt/mtd/app has 0777 permissions, allowing local users to replace an archive file (within that directory) to control what is extracted to RAM at boot time.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-10787 An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. /mnt/mtd/app has 0777 permissions, allowing local users to replace an archive file (within that directory) to control what is extracted to RAM at boot time.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T11:30:04.025Z

Reserved: 2018-11-07T00:00:00

Link: CVE-2018-19072

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-11-07T18:29:03.697

Modified: 2024-11-21T03:57:16.663

Link: CVE-2018-19072

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.