Executive brief
Brickcom security cameras, used for monitoring facilities and critical infrastructure, contain a flaw that allows unauthorized individuals to view live images. An attacker can access still images from the camera feed without needing a username or password. This could lead to the exposure of sensitive visual data and a breach of physical security monitoring.
Technical details
A missing authentication vulnerability (CWE-306) exists in multiple Brickcom camera models (Cube, Dome, Bullet, and Box) running firmware version 3.2.3.5.6. The vulnerability is located in the /ONVIF endpoint, which fails to enforce authentication requirements for snapshot requests. An attacker with local network access can programmatically or manually retrieve still images from the live camera feed without providing credentials. While the vendor did not respond to coordination efforts, CISA recommends isolating these devices from the internet and placing them behind firewalls or VPNs.
Affected products
- Brickcom Cube 3.2.3.5.6
- Brickcom Dome 3.2.3.5.6
- Brickcom Bullet 3.2.3.5.6
- Brickcom Box 3.2.3.5.6
Timeline
- 2026-06-11: advisory: CISA and NVD published the advisory.