CVE-2018-19076: Foscam c2 Application Firmware

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The FTP and RTSP services make it easier for attackers to conduct brute-force authentication attacks, because failed-authentication limits apply only to HTTP (not FTP or RTSP).

Affected products

  • Foscam c2 Application Firmware: version 2.72.1.32 only
  • Foscam c2 System Firmware: version 1.11.1.8 only
  • Opticam i5 Application Firmware: version 2.21.1.128 only
  • Opticam i5 System Firmware: version 1.5.2.11 only

Published 2018-11-07. Last modified 2026-06-17.