Back to overview

CVE-2026-65894

HIGH
8.7
CVSS 4.0
Description
This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP endpoints. A remote attacker could exploit this vulnerability by conducting brute-force attacks against HTTP endpoint on the targeted device. Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to live video snapshots from the targeted device.

Metadata

CVE ID
CVE-2026-65894
State
PUBLISHED
Assigner
CERT-In
Reserved
2026-07-23 10:19 UTC
Published
2026-07-27 07:16 UTC
Last updated
2026-07-27 07:16 UTC
Primary CWE
CWE-307
CWE-307 Improper restriction of excessive authentication att…
Vendor / Product
CP-Plus / EZ-P21 IP Camera
Sources
cve.org  ·  NVD

Severity & Metrics

8.7 HIGH CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products (1)
VendorProductPlatformVersions
CP-Plus EZ-P21 IP Camera version v4.8.8.1 and prior
Weakness (CWE)
CWESourceDescription
CWE-307 cna CWE-307 Improper restriction of excessive authentication attempts
CVSS scores (1)
ScoreSeverityVersionSourceVector
8.7 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Back to overview