Description
This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP endpoints. A remote attacker could exploit this vulnerability by conducting brute-force attacks against HTTP endpoint on the targeted device.



Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to live video snapshots from the targeted device.
Published: 2026-07-27
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Upgrade CP PLUS EZ-P21 IP Camera to latest firmware version 4.8.16.1 through OTA.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP endpoints. A remote attacker could exploit this vulnerability by conducting brute-force attacks against HTTP endpoint on the targeted device. Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to live video snapshots from the targeted device.
Title Improper Authentication Vulnerability in CP PLUS EZ-P21 IP Camera
First Time appeared Cp-plus
Cp-plus ez-p21 Ip Camera
Weaknesses CWE-307
CPEs cpe:2.3:a:cp-plus:ez-p21_ip_camera:version_v4.8.8.1_and_prior:*:*:*:*:*:*:*
Vendors & Products Cp-plus
Cp-plus ez-p21 Ip Camera
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Cp-plus Ez-p21 Ip Camera
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published:

Updated: 2026-07-27T07:16:33.504Z

Reserved: 2026-07-23T10:19:33.207Z

Link: CVE-2026-65894

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses
  • CWE-307

    Improper Restriction of Excessive Authentication Attempts