Junglewise Threat Intelligence

CVE-2026-65893: CP PLUS EZ-P21 IP Camera arbitrary code execution via debug feature

CVE-2026-65893 · Severity: info · CVSS 7 · Published 2026-07-27

Vendors: CP Plus.

Executive brief

CP PLUS EZ-P21 IP cameras, which are used for video surveillance and remote monitoring, contain a security flaw in their firmware's debug mode. An individual with physical access to the camera can insert a storage device containing malicious code to take full control of the hardware. This could lead to a total loss of privacy, unauthorized video access, or the device being used as a foothold for further attacks on the local network.

Technical details

This vulnerability (CWE-489) stems from an active debug feature enabled in the firmware of CP PLUS EZ-P21 IP cameras. An attacker with physical access can exploit this by placing arbitrary code on removable media (such as an SD card) and triggering its execution through the device's debug mechanism. Successful exploitation results in arbitrary code execution with elevated privileges. The vulnerability is addressed in firmware version 4.8.16.1, which is available via Over-the-Air (OTA) update.

Affected products

  • CP PLUS EZ-P21 IP Camera v4.8.8.1 and prior

Timeline

  • 2026-07-27: advisory: CERT-In published vulnerability note CIVN-2026-0380
  • 2026-07-27: patched: Firmware version 4.8.16.1 released to address the issue

References

Related threats