CameraRisk

CVE-2018-6830

Foscam

Published
9 July 2018
Last modified
17 June 2026
CVSS
7.5 v3.0
Severity
high
EPSS
2.6% (85th pct)
CISA KEV
Not listed
NVD status
Modified
Weaknesses
CWE-22

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Description

Directory traversal vulnerability in Foscam Cameras C1 Lite V3, and C1 V3 with firmware 2.82.2.33 and earlier, FI9800P V3, FI9803P V4, FI9851P V3, and FI9853EP V2 2.84.2.33 and earlier, FI9816P V3, FI9821EP V2, FI9821P V3, FI9826P V3, and FI9831P V3 2.81.2.33 and earlier, C1, C1 V2, C1 Lite, and C1 Lite V2 2.52.2.47 and earlier, FI9800P, FI9800P V2, FI9803P V2, FI9803P V3, and FI9851P V2 2.54.2.47 and earlier, FI9815P, FI9815P V2, FI9816P, and FI9816P V2, 2.51.2.47 and earlier, R2 and R4 2.71.1.59 and earlier, C2 and FI9961EP 2.72.1.59 and earlier, FI9900EP, FI9900P, and FI9901EP 2.74.1.59 and earlier, FI9928P 2.74.1.58 and earlier, FI9803EP and FI9853EP 2.22.2.31 and earlier, FI9803P and FI9851P 2.24.2.31 and earlier, FI9821P V2, FI9826P V2, FI9831P V2, and FI9821EP 2.21.2.31 and earlier, FI9821W V2, FI9831W, FI9826W, FI9821P, FI9831P, and FI9826P 2.11.1.120 and earlier, FI9818W V2 2.13.2.120 and earlier, FI9805W, FI9804W, FI9804P, FI9805E, and FI9805P 2.14.1.120 and earlier, FI9828P, and FI9828W 2.13.1.120 and earlier, and FI9828P V2 2.11.1.133 and earlier allows remote attackers to delete arbitrary files via a .. (dot dot) in the URI path component.

Exploitation

Not listed in the CISA Known Exploited Vulnerabilities catalogue as of 2026.09.04. That is an absence of confirmed public exploitation, not evidence that exploitation has not occurred. EPSS models a 2.6% probability of exploitation activity in the next 30 days.

Affected products

ProductVendorTypeVersions named
C1 Foscam unknown 2, 2.52.2.37, 2.52.2.43, 3 +2
C1 LITE Foscam unknown 2, 3, <= 2.52.2.47, <= 2.82.2.33
C2 Foscam unknown <= 2.72.1.59
FI9800P Foscam unknown 2, 3, <= 2.54.2.47, <= 2.81.2.33
FI9803EP Foscam unknown <= 2.22.2.31
FI9803P Foscam unknown 2, 3, <= 2.24.2.31, <= 2.54.2.47
FI9804P Foscam unknown <= 2.14.1.120
FI9804W Foscam unknown <= 2.14.1.120
FI9805E Foscam unknown 4.02.r12.00018510.10012.143900.00000, <= 2.14.1.120
FI9805P Foscam unknown <= 2.14.1.120
FI9805W Foscam unknown <= 2.14.1.120
FI9815P Foscam unknown 2, <= 2.51.2.47
FI9816P Foscam unknown 2, <= 2.51.2.47
FI9818W Foscam unknown 2, <= 2.13.2.120
FI9821EP Foscam unknown 2, <= 2.21.2.31, <= 2.81.2.33
FI9821P Foscam unknown 2, 3, <= 2.11.1.120, <= 2.21.2.31 +1
FI9821W Foscam unknown 2, <= 2.11.1.120
FI9826P Foscam unknown 2, 3, <= 2.11.1.120, <= 2.21.2.31 +1
FI9826W Foscam unknown <= 2.11.1.120
FI9828P Foscam unknown 2, <= 2.11.1.133, <= 2.13.1.120
FI9828W Foscam unknown <= 2.13.1.120
FI9831P Foscam unknown 2, 3, <= 2.11.1.120, <= 2.21.2.31 +1
FI9831W Foscam unknown <= 2.11.1.120
FI9851P Foscam unknown 2, <= 2.24.2.31, <= 2.54.2.47
FI9853EP Foscam unknown <= 2.22.2.31
FI9900EP Foscam unknown <= 2.74.1.59
FI9900P Foscam unknown <= 2.74.1.59
FI9901EP Foscam unknown <= 2.74.1.59
FI9928P Foscam unknown <= 2.74.1.58
FI9961EP Foscam unknown <= 2.72.1.59
R2 Foscam unknown <= 2.71.1.59
R4 Foscam unknown <= 2.71.1.59

References

Vendor advisory and patch

CVE-2018-6830 at NVD

Record assembled from NVD, CISA KEV 2026.09.04 and FIRST EPSS 2026-09-04. Affected products are those NVD's CPE configuration names that fall inside this site's scope; a CVE may affect products outside it.