CVE-2017-5674: Embedthis GoAhead
Critical severity, CVSS 9.8. EPSS: 21.6% chance of exploitation in the next 30 days.
A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft a malformed HTTP ("GET system.ini HTTP/1.1\n\n" - note the lack of "/" in the path field of the request) request that will disclose the configuration file with the login password.
Affected products
- Embedthis GoAhead: affected versions not specified
Published 2017-03-13. Last modified 2026-06-17.