CVE-2026-100906: Eyeplus ONVIF Device GetUsers information disclosure
A vulnerability was detected in Eyeplus 57.0.0.0308. The affected element is the function GetUsers of the file /onvif/Device of the component ONVIF. The manipulation results in information disclosure. The attack can be executed remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be executed remotely and requires no privileges or user interaction, according to the supplied vector. An exposed ONVIF Device endpoint is therefore the relevant attack surface.
What information can be obtained through the vulnerable endpoint?
The data identifies GetUsers at /onvif/Device as the affected function and characterizes the impact as information disclosure. It does not specify the exact fields or user information returned.
Is exploit code available?
Yes. The supplied data states that the exploit is public and may be used, increasing the likelihood of opportunistic exploitation.