CVE-2026-65894 HIGH

CVE-2026-65894: Improper Authentication Vulnerability in CP PLUS EZ-P21 IP Camera

Vendor Cp-Plus
Product EZ-P21 IP Camera
Weakness CWE-307 · Brute force
Published July 27, 2026
Last update July 27, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP endpoints. A remote attacker could exploit this vulnerability by conducting brute-force attacks against HTTP endpoint on the targeted device. Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to live video snapshots from the targeted device.

Key dates

02Disclosure timeline

July 27, 2026 CVE published
July 27, 2026 Record updated

Related vulnerabilities

04Related CVE