Improper Authentication in CP PLUS EZ-P21 IP Camera
CVE-2026-65894

8.7HIGH

Key Information:

Vendor

Cp-plus

Vendor
CVE Published:
27 July 2026

What is CVE-2026-65894?

The CP PLUS EZ-P21 IP Camera is vulnerable due to improper authentication of HTTP endpoints. This flaw allows attackers to execute brute-force attacks, potentially gaining unauthorized access to live video snapshots from the device. Exploitation of this vulnerability poses significant risks to the privacy and security of users, making it crucial for affected users to implement necessary security measures.

Affected Version(s)

EZ-P21 IP Camera version v4.8.8.1 and prior

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability is reported by a team of security researchers including Vishwa V and Sathya Priya S from SRMIST Ramapuram. Tiyyagura Venkata Shesha Shaina Reddy and Isukapalli Venkata Mythreya Kumara Sarma from Vignan University. Deven Lunkad and S. Venkatesan from IIIT Allahabad.
.