PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-100906 Eyeplus CVE debrief

CVE-2026-100906 is a medium-severity vulnerability detected in Eyeplus 57.0.0.0308, specifically in the GetUsers function of the /onvif/Device component, leading to information disclosure via ONVIF. The vulnerability has a CVSS score of 5.5 and is classified as MEDIUM severity. The attack can be executed remotely, and the exploit is now public. Defenders should assess their exposure, verify affected systems, and plan for remediation. This vulnerability affects ONVIF-enabled Eyeplus devices, potentially exposing sensitive user data.

Vendor
Eyeplus
Product
Eyeplus 57.0.0.0308
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-28
Original CVE updated
2026-09-28
Advisory published
2026-09-28
Advisory updated
2026-09-28

Who should care

Defenders responsible for managing and securing Eyeplus devices, especially those using ONVIF-enabled components, should assess their exposure to this vulnerability. IT and security teams overseeing networked security devices should verify if their inventory includes affected versions and plan for remediation.

Why it matters

CVE-2026-100906 is a medium-severity vulnerability in Eyeplus 57.0.0.0308 that can lead to information disclosure via the ONVIF protocol. Defenders should verify exposure, update device configurations, and monitor for exploitation attempts.

  • Verify exposure of ONVIF-enabled Eyeplus devices to potential information disclosure
  • Assess and limit access to ONVIF components to prevent unauthorized data access
  • Monitor network traffic for signs of exploitation attempts targeting this vulnerability

Technical summary

The vulnerability is located in the GetUsers function of the /onvif/Device component in Eyeplus 57.0.0.0308. This function is part of the ONVIF (Open Network Video Interface Forum) protocol, which is used for communication between IP-based security devices. The vulnerability allows for information disclosure, potentially exposing sensitive user data. The CVSS score of 5.5 indicates a medium severity level, with the attack vector being network-based (AV:N), requiring low attack complexity (AC:L), and no privileges (PR:N).

Defensive priority

Defenders should prioritize verifying exposure of ONVIF-enabled Eyeplus devices, especially those accessible remotely.

Recommended defensive actions

  • Verify exposure of ONVIF-enabled Eyeplus devices, especially those accessible remotely
  • Review and update device configurations to limit access to ONVIF components
  • Monitor for potential exploitation attempts targeting this vulnerability
  • Assign an owner to track remediation progress for affected systems
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD detail page provide official information about the vulnerability. Additional details are available from source references, including a GitHub advisory and Vuldb entries. The vulnerability has been publicly disclosed, and defenders should verify exposure of ONVIF-enabled Eyeplus devices, especially those accessible remotely. The information provided is based on available data and may not be exhaustive.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-100906 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-100906

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-100906 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100906

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.