Impact
This vulnerability is an authentication bypass (CWE-307) that allows a remote attacker to brute‑force HTTP endpoints on the CP‑Plus EZ‑P21 IP Camera. Successful exploitation results in unauthorized viewing of live video snapshots, potentially exposing confidential visual data. No mention of data modification or denial of service is made, so the primary concern is confidentiality breach.
Affected Systems
CP‑Plus EZ‑P21 IP Camera models running firmware versions 4.8.8.1 and prior are affected. The issue is present in all releases up to and including 4.8.8.1.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability, and the EPSS score of < 1% indicates a very low but non‑zero probability of exploitation. The vulnerability is listed as not in the CISA KEV catalog. Based on the description, the likely attack vector is a remote network actor that can reach the device’s HTTP management interface, and brute‑force attempts are the primary exploitation method. Given the lack of additional mitigations in the device, the risk to any exposed deployment is considerable.
OpenCVE Enrichment