Insecure Debug Feature in CP PLUS EZ-P21 IP Camera
CVE-2026-65893
7HIGH
What is CVE-2026-65893?
A vulnerability exists in the CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware. This flaw permits an attacker, with physical access to the device, to exploit the debug mechanism by loading arbitrary code via removable media. If successfully executed, this could grant the attacker elevated privileges, allowing unauthorized control over the targeted IP camera.
Affected Version(s)
EZ-P21 IP Camera version v4.8.8.1 and prior
References
CVSS V4
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability is reported by a team of security researchers including Isukapalli Venkata Mythreya Kumara Sarma, Tiyyagura Venkata Shesha Shaina Reddy and Naga Venkatesh Durga Sai Krishna from Vignan University. Vishwa V and Sathya Priya S from SRMIST Ramapuram. Deven Lunkad and S. Venkatesan from IIIT Allahabad.
