Junglewise Threat Intelligence

CVE-2024-58330: Bosch IP Camera missing authentication in video analytics

CVE-2024-58330 · Severity: high · CVSS 7.5 · Published 2026-07-23

Executive brief

Bosch IP cameras in the CPP13 and CPP14 families are affected by a security flaw that allows unauthorized individuals to access video analytics data. These cameras are used for surveillance and automated monitoring; an exploit could allow an attacker to view sensitive event logs and metadata without a password. This could lead to the exposure of operational intelligence or privacy-sensitive information regarding monitored areas.

Technical details

A missing authentication check (CWE-284) exists in the firmware of Bosch IP cameras belonging to the CPP13 and CPP14 hardware platforms. An unauthenticated attacker with network access to the device can exploit this vulnerability to retrieve video analytics event data. This data typically includes metadata and logs generated by the camera's automated detection features. The vulnerability is exploitable remotely without user interaction. Affected firmware versions include those up to 8.91 for CPP13 and 9.10 for CPP14.

Affected products

  • Bosch Camera Firmware (CPP13) <= 8.91
  • Bosch Camera Firmware (CPP14) <= 9.10

Timeline

  • 2026-07-23: advisory: Initial disclosure by Bosch PSIRT

References