CameraRisk

CVE-2018-8072

Edimax

Published
26 April 2018
Last modified
17 June 2026
CVSS
8.8 v3.0
Severity
high
EPSS
2.8% (86th pct)
CISA KEV
Not listed
NVD status
Modified
Weaknesses
CWE-787

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

An issue was discovered on EDIMAX IC-3140W through 3.06, IC-5150W through 3.09, and IC-6220DC through 3.06 devices. The ipcam_cgi binary contains a stack-based buffer overflow that is possible to trigger from a remote unauthenticated /camera-cgi/public/getsysyeminfo.cgi?action=VALUE_HERE HTTP request: if the VALUE_HERE length is more than 0x400 (1024), it is possible to overwrite other values located on the stack due to an incorrect use of the strcpy() function.

Exploitation

Not listed in the CISA Known Exploited Vulnerabilities catalogue as of 2026.09.04. That is an absence of confirmed public exploitation, not evidence that exploitation has not occurred. EPSS models a 2.8% probability of exploitation activity in the next 30 days.

Affected products

ProductVendorTypeVersions named
IC-3140W Edimax unknown 3.07, 3.11, <= 3.06
IC-5150W Edimax unknown <= 3.06, <= 3.09
IC-6220DC Edimax unknown <= 3.06

References

Vendor advisory and patch

CVE-2018-8072 at NVD

Record assembled from NVD, CISA KEV 2026.09.04 and FIRST EPSS 2026-09-04. Affected products are those NVD's CPE configuration names that fall inside this site's scope; a CVE may affect products outside it.