This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP endpoints. A remote attacker could exploit this vulnerability by conducting brute-force attacks against HTTP endpoint on the targeted device. Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to live video snapshots from the targeted device.
History

Mon, 27 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP endpoints. A remote attacker could exploit this vulnerability by conducting brute-force attacks against HTTP endpoint on the targeted device. Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to live video snapshots from the targeted device.
Title Improper Authentication Vulnerability in CP PLUS EZ-P21 IP Camera
First Time appeared Cp-plus
Cp-plus ez-p21 Ip Camera
Weaknesses CWE-307
CPEs cpe:2.3:a:cp-plus:ez-p21_ip_camera:version_v4.8.8.1_and_prior:*:*:*:*:*:*:*
Vendors & Products Cp-plus
Cp-plus ez-p21 Ip Camera
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published: 2026-07-27T07:16:33.504Z

Updated: 2026-07-27T10:25:55.518Z

Reserved: 2026-07-23T10:19:33.207Z

Link: CVE-2026-65894

cve-icon Vulnrichment

Updated: 2026-07-27T10:25:51.461Z

cve-icon NVD

No data.

cve-icon Redhat

No data.