CVE-2018-20299: Bosch 360-Indoor Camera Firmware

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

An issue was discovered in several Bosch Smart Home cameras (360 degree indoor camera and Eyes outdoor camera) with firmware before 6.52.4. A malicious client could potentially succeed in the unauthorized execution of code on the device via the network interface, because there is a buffer overflow in the RCP+ parser of the web server.

Affected products

  • Bosch 360-Indoor Camera Firmware: before 6.52.4 (fixed in 6.52.4)
  • Bosch Eyes Outdoor Camera Firmware: before 6.52.4 (fixed in 6.52.4)

Published 2018-12-19. Last modified 2026-06-17.