Executive brief
Brickcom security cameras, used for monitoring facilities in sectors like healthcare and manufacturing, ship with default login credentials. An attacker can use these well-known passwords to gain unauthorized access to live video feeds and administrative settings. This could lead to the exposure of sensitive visual information or the complete takeover of the camera hardware.
Technical details
The vulnerability (CWE-1392) exists because Brickcom cameras ship with static, default credentials that are not forced to change upon initial setup. An attacker with local access to the device's network interface can use these credentials to bypass authentication. Successful exploitation allows for unauthorized access to live video streams and full administrative control over the device. CISA reports that the vendor did not respond to coordination efforts, and no official patch is currently available; users are advised to change default passwords immediately and isolate devices from the internet.
Affected products
- Brickcom Brickcom Cube 3.2.3.5.6
- Brickcom Brickcom Dome 3.2.3.5.6
- Brickcom Brickcom Bullet 3.2.3.5.6
- Brickcom Brickcom Box 3.2.3.5.6
Timeline
- 2026-06-11: disclosed: Initial publication of ICSA-26-162-03 by CISA.
- 2026-06-11: advisory