Description
This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP endpoints. A remote attacker could exploit this vulnerability by conducting brute-force attacks against HTTP endpoint on the targeted device.



Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to live video snapshots from the targeted device.
Published: 2026-07-27
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an authentication bypass (CWE-307) that allows a remote attacker to brute‑force HTTP endpoints on the CP‑Plus EZ‑P21 IP Camera. Successful exploitation results in unauthorized viewing of live video snapshots, potentially exposing confidential visual data. No mention of data modification or denial of service is made, so the primary concern is confidentiality breach.

Affected Systems

CP‑Plus EZ‑P21 IP Camera models running firmware versions 4.8.8.1 and prior are affected. The issue is present in all releases up to and including 4.8.8.1.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity vulnerability, and the EPSS score of < 1% indicates a very low but non‑zero probability of exploitation. The vulnerability is listed as not in the CISA KEV catalog. Based on the description, the likely attack vector is a remote network actor that can reach the device’s HTTP management interface, and brute‑force attempts are the primary exploitation method. Given the lack of additional mitigations in the device, the risk to any exposed deployment is considerable.

Generated by OpenCVE AI on August 3, 2026 at 17:58 UTC.

Remediation

Vendor Solution

Upgrade CP PLUS EZ-P21 IP Camera to latest firmware version 4.8.16.1 through OTA.


OpenCVE Recommended Actions

  • Upgrade CP PLUS EZ‑P21 IP Camera to firmware version 4.8.16.1 via OTA.
  • If an immediate firmware upgrade is infeasible, block or restrict access to the camera’s HTTP endpoints from untrusted networks using a firewall or access control list.
  • Enable logging of authentication attempts and monitor for repeated failures; consider rate limiting or account lockout if the device supports it.

Generated by OpenCVE AI on August 3, 2026 at 17:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP endpoints. A remote attacker could exploit this vulnerability by conducting brute-force attacks against HTTP endpoint on the targeted device. Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to live video snapshots from the targeted device.
Title Improper Authentication Vulnerability in CP PLUS EZ-P21 IP Camera
First Time appeared Cp-plus
Cp-plus ez-p21 Ip Camera
Weaknesses CWE-307
CPEs cpe:2.3:a:cp-plus:ez-p21_ip_camera:version_v4.8.8.1_and_prior:*:*:*:*:*:*:*
Vendors & Products Cp-plus
Cp-plus ez-p21 Ip Camera
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Cp-plus Ez-p21 Ip Camera
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published:

Updated: 2026-07-27T10:25:55.518Z

Reserved: 2026-07-23T10:19:33.207Z

Link: CVE-2026-65894

cve-icon Vulnrichment

Updated: 2026-07-27T10:25:51.461Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T08:16:23.157

Modified: 2026-07-27T20:32:11.620

Link: CVE-2026-65894

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T18:00:11Z

Weaknesses
  • CWE-307

    Improper Restriction of Excessive Authentication Attempts