The CVE-2026-65894 vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP endpoints. A remote attacker could exploit this vulnerability by conducting brute-force attacks against HTTP endpoint on the targeted device. Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to live video snapshots from the targeted device. The vulnera [truncated]
The CVE-2026-65893 vulnerability exists in the CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware. An attacker with physical access could exploit this vulnerability by placing arbitrary code on removable media and triggering their execution through the debug mechanism. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code with elevat [truncated]
A stored cross-site scripting (XSS) vulnerability in certain 1xxx series Network Video Recorder (NVR) devices allows authenticated attackers with high privileges to inject malicious scripts that persist on the device backend. When administrators or users subsequently access affected pages, the stored scripts execute in their browsers, potentially enabling session hijacking, unauthorized actions, or data t [truncated]
CP Plus Wi-Fi Camera devices contain a medium-severity vulnerability (CVSS 4.0: 5.2) stemming from improper protection of sensitive information in runtime memory (CWE-312). An attacker with physical access can extract cryptographic private keys, Wi-Fi credentials, and configuration data by interfacing with the UART port and performing memory extraction from RAM. Successful exploitation enables unauthorize [truncated]