CVE-2026-65894: Improper Authentication Vulnerability in CP PLUS EZ-P21 IP Camera
This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP endpoints. A remote attacker could exploit this vulnerability by conducting brute-force attacks against HTTP endpoint on the targeted device.
Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to live video snapshots from the targeted device.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
CP PLUS EZ-P21 IP Camerato a version that resolves this vulnerability.Fixed in 4.8.16.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-65894?
CVE-2026-65894 has a high severity rating of 8.7.
How do I fix CVE-2026-65894?
To fix CVE-2026-65894, ensure that proper authentication mechanisms are enforced on all HTTP endpoints of the CP PLUS EZ-P21 IP Camera.
What type of vulnerability is identified in CVE-2026-65894?
CVE-2026-65894 is classified as an improper authentication vulnerability.
What can a remote attacker do with CVE-2026-65894?
A remote attacker could exploit CVE-2026-65894 by conducting brute-force attacks against the HTTP endpoint of the targeted CP PLUS EZ-P21 IP Camera.
When was CVE-2026-65894 published?
CVE-2026-65894 was published on July 27, 2026.