SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-65894

HIGH · CVSS 8.7 EPSS 0.40% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

The CP PLUS EZ-P21 IP Camera is vulnerable due to improper authentication of its HTTP endpoints, allowing remote attackers to perform brute-force attacks. If exploited, this vulnerability could enable unauthorized access to live video feeds from the device. Organizations using this camera model should prioritize addressing this issue to safeguard their video surveillance systems.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-65894
Severity
HIGH
CVSS
8.7
EPSS
0.40%

Original NVD Description

This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP endpoints. A remote attacker could exploit this vulnerability by conducting brute-force attacks against HTTP endpoint on the targeted device. Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to live video snapshots from the targeted device.