CVE-2018-11560: Insteon 2864-222 Firmware

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

The webService binary on Insteon HD IP Camera White 2864-222 devices has a stack-based Buffer Overflow leading to Control-Flow Hijacking via a crafted usr key, as demonstrated by a long remoteIp parameter to cgi-bin/CGIProxy.fcgi on port 34100.

Affected products

  • Insteon 2864-222 Firmware: affected versions not specified

Published 2018-06-23. Last modified 2026-06-17.