Impact
The CP PLUS EZ-P21 IP camera contains an insecure debug feature that allows an attacker with physical access to place code on removable media and trigger its execution. Successful exploitation results in arbitrary code execution with elevated privileges, effectively granting the attacker full control over the camera’s operating system and any services running on it.
Affected Systems
Vulnerable devices are CP-Plus EZ-P21 IP cameras that run firmware version 4.8.8.1 or earlier. The recommended fix is the latest firmware, 4.8.16.1, which removes the insecure debug functionality.
Risk and Exploitability
The CVSS score of 7 indicates a high severity vulnerability. The EPSS score of less than 1% indicates a very low probability of exploitation, and the issue is not included in the CISA KEV catalog. The attack requires physical possession of the device to insert removable media, but once that condition is met the exploitation path is straightforward and grants full system privileges.
OpenCVE Enrichment