Back to overview

CVE-2026-65893

HIGH
7.0
CVSS 4.0
Description
This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware. An attacker with physical access could exploit this vulnerability by placing arbitrary code on removable media and triggering their execution through the debug mechanism. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code with elevated privileges on the targeted device.

Metadata

CVE ID
CVE-2026-65893
State
PUBLISHED
Assigner
CERT-In
Reserved
2026-07-23 10:19 UTC
Published
2026-07-27 07:12 UTC
Last updated
2026-07-27 07:12 UTC
Primary CWE
CWE-489
CWE-489 Active debug code
Vendor / Product
CP-Plus / EZ-P21 IP Camera
Sources
cve.org  ·  NVD

Severity & Metrics

7.0 HIGH CVSS 4.0
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products (1)
VendorProductPlatformVersions
CP-Plus EZ-P21 IP Camera version v4.8.8.1 and prior
Weakness (CWE)
CWESourceDescription
CWE-489 cna CWE-489 Active debug code
CVSS scores (1)
ScoreSeverityVersionSourceVector
7.0 HIGH 4.0 cna CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Back to overview