
[CIVN-2026-0380] Multiple Vulnerabilities in CP PLUS EZ-P21 IP Camera
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in CP PLUS EZ-P21 IP Camera
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Systems Affected
CP PLUS EZ-P21 IP Camera – version v4.8.8.1 and prior
Overview
Multiple vulnerabilities have been reported in CP PLUS EZ-P21 IP Camera, which could allow an attacker to execute arbitrary code and gain unauthorized access to live video snapshots from the targeted device.
Target Audience:
End-users/ Administrators using CP PLUS EZ-P21 IP Camera
Risk Assessment:
Risk of arbitrary code execution and improper authentication
Impact Assessment:
Potential for arbitrary code execution with elevated privileges and unauthorized access.
Description
The CP PLUS EZ-P21 IP Camera is an Internet Protocol (IP) based surveillance camera used for video monitoring and network based access to camera functions and video snapshots.
1. Arbitrary Code Execution Vulnerability ( CVE-2026-65893 )
This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware.
An attacker with physical access could exploit this vulnerability by placing arbitrary code on removable media and triggering their execution through the debug mechanism.
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code with elevated privileges on the targeted device.
2. Improper Authentication Vulnerability ( CVE-2026-65894 )
This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP endpoints. A remote attacker could exploit this vulnerability by conducting brute-force attacks against HTTP endpoint on the targeted device.
Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to live video snapshots from the targeted device.
Credit
These vulnerabilities are reported by the following team of security researchers:
CVE-2026-65893: Isukapalli Venkata Mythreya Kumara Sarma, Tiyyagura Venkata Shesha Shaina Reddy and Naga Venkatesh Durga Sai Krishna from Vignan University. Vishwa V and Sathya Priya S from SRMIST Ramapuram. Deven Lunkad and S. Venkatesan from IIIT Allahabad
CVE-2026-65894: Vishwa V and Sathya Priya S from SRMIST Ramapuram. Tiyyagura Venkata Shesha Shaina Reddy and Isukapalli Venkata Mythreya Kumara Sarma from Vignan University. Deven Lunkad and S. Venkatesan from IIIT Allahabad
Solution
Upgrade CP PLUS EZ-P21 IP Camera to latest firmware version 4.8.16.1 through OTA.
Vendor Information
CP Plus
https://cpplusworld.com/products
References
CP Plus
https://cpplusworld.com/products
CVE Name
CVE-2026-65893
CVE-2026-65894
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpqAf8ACgkQ3jCgcSdc
ys+2NBAAoS+fKzTtVz3vsouPWQi5JCxcEm0Ecat2sTJGfsamjGs9ylkae79Nyt68
tjJuXkJKqa4lvnnG2yKBxbIFhcybM+R46E6zlVVghjhpd5HasqkRj8oM4MzX63w2
dnolBR8zn21G/amOeWYgn7j2s7psp/Sls/8JP8yeqrWlVnwrXkijv8a64+AO2BEo
9dJ74hsP9qxY7P2oI72MpsQZQ6qemuUWxl4azY/2McbCqiHznksduhTTaaZgXs9S
i88Hb5sA7iAT+79Hak56Gc/MRBGmxBByZma/mYht+iB7QuLbUWQX44PO8UKptI4z
BufVEcIY/arLt6SI3Uv1yKm5rdauy1gdbrqj8dwX2gszm69Obn6t/KUQWlCFP7Bt
fJRNTpo+HNd7IIyEeHmOSuYl5ESMj4Xa6lRxpjxzF+iPp6ivTMUduK/MVLj32u/Z
rDsOU6Juy25FAFz5MxSQHWem+gUZYZhCuz5iIrgl6Uhz43x+7wArgymOEeON9Gbd
YIdeu0n2bGcxyxQz+IP5mmj3KvRi6SCA5tEvXDVmcQWol50PoJyY5kzsqfEtlZqu
OvKl7TYl270dRDOWXvlBYwOoQG9NeT8tWek5qkoQrBGZWrMHPep/FSaeWiZaNkX2
yXLMbW17rhkTb2bTo7icm8mLUPhHTvpgCAhwIuycMAavWoenv0w=
=lDXo
—–END PGP SIGNATURE—–


