PatchSiren cyber security CVE debrief
CVE-2026-100906 Eyeplus CVE debrief
CVE-2026-100906 is a medium-severity vulnerability detected in Eyeplus 57.0.0.0308, specifically in the GetUsers function of the /onvif/Device component, leading to information disclosure via ONVIF. The vulnerability has a CVSS score of 5.5 and is classified as MEDIUM severity. The attack can be executed remotely, and the exploit is now public. Defenders should assess their exposure, verify affected systems, and plan for remediation. This vulnerability affects ONVIF-enabled Eyeplus devices, potentially exposing sensitive user data.
- Vendor
- Eyeplus
- Product
- Eyeplus 57.0.0.0308
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-28
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-28
- Advisory updated
- 2026-09-28
Who should care
Defenders responsible for managing and securing Eyeplus devices, especially those using ONVIF-enabled components, should assess their exposure to this vulnerability. IT and security teams overseeing networked security devices should verify if their inventory includes affected versions and plan for remediation.
Why it matters
CVE-2026-100906 is a medium-severity vulnerability in Eyeplus 57.0.0.0308 that can lead to information disclosure via the ONVIF protocol. Defenders should verify exposure, update device configurations, and monitor for exploitation attempts.
- Verify exposure of ONVIF-enabled Eyeplus devices to potential information disclosure
- Assess and limit access to ONVIF components to prevent unauthorized data access
- Monitor network traffic for signs of exploitation attempts targeting this vulnerability
Technical summary
The vulnerability is located in the GetUsers function of the /onvif/Device component in Eyeplus 57.0.0.0308. This function is part of the ONVIF (Open Network Video Interface Forum) protocol, which is used for communication between IP-based security devices. The vulnerability allows for information disclosure, potentially exposing sensitive user data. The CVSS score of 5.5 indicates a medium severity level, with the attack vector being network-based (AV:N), requiring low attack complexity (AC:L), and no privileges (PR:N).
Defensive priority
Defenders should prioritize verifying exposure of ONVIF-enabled Eyeplus devices, especially those accessible remotely.
Recommended defensive actions
- Verify exposure of ONVIF-enabled Eyeplus devices, especially those accessible remotely
- Review and update device configurations to limit access to ONVIF components
- Monitor for potential exploitation attempts targeting this vulnerability
- Assign an owner to track remediation progress for affected systems
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD detail page provide official information about the vulnerability. Additional details are available from source references, including a GitHub advisory and Vuldb entries. The vulnerability has been publicly disclosed, and defenders should verify exposure of ONVIF-enabled Eyeplus devices, especially those accessible remotely. The information provided is based on available data and may not be exhaustive.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-100906 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-100906
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-100906 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100906
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/devjanger/iot-advisories/blob/main/EYEPLUS-GetUsers-Unauth-Plaintext-Password.md
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-100906
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/919771
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/410857
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/410857/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.