Junglewise Threat Intelligence

CVE-2026-65894: CP PLUS EZ-P21 IP Camera improper authentication in HTTP endpoints

CVE-2026-65894 · Severity: info · CVSS 8.7 · Published 2026-07-27

Vendors: CP Plus.

Executive brief

CP PLUS EZ-P21 IP cameras, which are used for remote video monitoring and surveillance, are vulnerable to unauthorized access. An attacker can use automated tools to guess credentials for the camera's web interface, potentially allowing them to view live video snapshots without permission. This could lead to a significant breach of privacy and physical security for organizations or individuals using these devices.

Technical details

The vulnerability is classified as an improper restriction of excessive authentication attempts (CWE-307) within the HTTP endpoints of the CP PLUS EZ-P21 IP Camera. The root cause is a lack of adequate rate limiting or account lockout mechanisms, which allows a remote, unauthenticated attacker to perform brute-force attacks against the device's web interface. Successful exploitation grants the attacker the ability to retrieve live video snapshots from the camera. The issue affects firmware versions v4.8.8.1 and prior, and a fix is available in firmware version 4.8.16.1.

Affected products

  • CP PLUS EZ-P21 IP Camera v4.8.8.1 and prior

Timeline

  • 2026-07-27: advisory: Initial advisory published by CERT-In
  • 2026-07-27: patched: Firmware version 4.8.16.1 released to address the issue

References

Related threats