Executive brief
CP PLUS EZ-P21 IP cameras, which are used for remote video monitoring and surveillance, are vulnerable to unauthorized access. An attacker can use automated tools to guess credentials for the camera's web interface, potentially allowing them to view live video snapshots without permission. This could lead to a significant breach of privacy and physical security for organizations or individuals using these devices.
Technical details
The vulnerability is classified as an improper restriction of excessive authentication attempts (CWE-307) within the HTTP endpoints of the CP PLUS EZ-P21 IP Camera. The root cause is a lack of adequate rate limiting or account lockout mechanisms, which allows a remote, unauthenticated attacker to perform brute-force attacks against the device's web interface. Successful exploitation grants the attacker the ability to retrieve live video snapshots from the camera. The issue affects firmware versions v4.8.8.1 and prior, and a fix is available in firmware version 4.8.16.1.
Affected products
- CP PLUS EZ-P21 IP Camera v4.8.8.1 and prior
Timeline
- 2026-07-27: advisory: Initial advisory published by CERT-In
- 2026-07-27: patched: Firmware version 4.8.16.1 released to address the issue