Description
This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware.

An attacker with physical access could exploit this vulnerability by placing arbitrary code on removable media and triggering their execution through the debug mechanism.



Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code with elevated privileges on the targeted device.
Published: 2026-07-27
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CP PLUS EZ-P21 IP camera contains an insecure debug feature that allows an attacker with physical access to place code on removable media and trigger its execution. Successful exploitation results in arbitrary code execution with elevated privileges, effectively granting the attacker full control over the camera’s operating system and any services running on it.

Affected Systems

Vulnerable devices are CP-Plus EZ-P21 IP cameras that run firmware version 4.8.8.1 or earlier. The recommended fix is the latest firmware, 4.8.16.1, which removes the insecure debug functionality.

Risk and Exploitability

The CVSS score of 7 indicates a high severity vulnerability. The EPSS score of less than 1% indicates a very low probability of exploitation, and the issue is not included in the CISA KEV catalog. The attack requires physical possession of the device to insert removable media, but once that condition is met the exploitation path is straightforward and grants full system privileges.

Generated by OpenCVE AI on August 4, 2026 at 14:04 UTC.

Remediation

Vendor Solution

Upgrade CP PLUS EZ-P21 IP Camera to latest firmware version 4.8.16.1 through OTA.


OpenCVE Recommended Actions

  • Upgrade the camera firmware to version 4.8.16.1 via the official OTA update channel.
  • Disable or remove the debug feature from the camera’s configuration to eliminate the vulnerable entry point.
  • Restrict physical access to the camera and, if possible, disable or secure removable media ports to prevent insertion of malicious code.

Generated by OpenCVE AI on August 4, 2026 at 14:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware. An attacker with physical access could exploit this vulnerability by placing arbitrary code on removable media and triggering their execution through the debug mechanism. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code with elevated privileges on the targeted device.
Title Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera
First Time appeared Cp-plus
Cp-plus ez-p21 Ip Camera
Weaknesses CWE-489
CPEs cpe:2.3:a:cp-plus:ez-p21_ip_camera:version_v4.8.8.1_and_prior:*:*:*:*:*:*:*
Vendors & Products Cp-plus
Cp-plus ez-p21 Ip Camera
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Cp-plus Ez-p21 Ip Camera
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published:

Updated: 2026-07-27T10:37:56.515Z

Reserved: 2026-07-23T10:19:33.207Z

Link: CVE-2026-65893

cve-icon Vulnrichment

Updated: 2026-07-27T10:37:49.439Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T08:16:23.010

Modified: 2026-07-27T20:32:11.620

Link: CVE-2026-65893

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T14:15:10Z

Weaknesses