CVE-2026-65894
CP-Plus · EZ-P21 IP Camera
The CP-Plus EZ-P21 IP Camera contains an authentication bypass vulnerability due to improper restriction of excessive authentication attempts on HTTP endpoints.
Executive summary
An unauthenticated remote attacker can exploit an authentication flaw in the CP-Plus EZ-P21 IP Camera to gain unauthorized access to sensitive device functionality.
Vulnerability
The device fails to properly restrict authentication attempts, allowing for potential bypass or brute-force scenarios on HTTP endpoints. The vulnerability is exploitable by an unauthenticated remote attacker.
Business impact
The CVSS score of 8.7 highlights the severe risk posed by this vulnerability, as it allows unauthorized access to camera control functions or video streams. This could lead to total loss of privacy, unauthorized surveillance, or the integration of the device into a botnet for further attacks on the internal network.
Remediation
Immediate Action: Upgrade the firmware of the CP-Plus EZ-P21 IP Camera to version 4.8.16.1 or later via the over-the-air (OTA) update mechanism.
Proactive Monitoring: Review device access logs for unusual patterns of failed login attempts or unauthorized connection requests from unknown IP addresses.
Compensating Controls: Isolate IP cameras on a dedicated VLAN with no direct internet exposure and utilize a firewall to restrict access to the device management interface.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Immediate firmware updates are required to secure these devices. If an OTA update is not immediately feasible, the devices must be removed from public-facing network segments to prevent exploitation of the authentication mechanism.