PatchSiren

Eyeplus CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Eyeplus CVE published 2026-09-28

CVE-2026-100908

CVE-2026-100908 is a high-severity vulnerability in Eyeplus 57.0.0.0308, affecting the p2pcam HTTP Parser component. A remote attacker can exploit this vulnerability to cause a stack-based buffer overflow. The CVE record was published on 2026-09-28T05:16:29.877Z and has not been modified since then. Defenders should verify exposure and assess remote exploitation feasibility. The vulnerability requires ver [truncated]

MEDIUM Eyeplus CVE published 2026-09-28

CVE-2026-100906

CVE-2026-100906 is a medium-severity vulnerability detected in Eyeplus 57.0.0.0308, specifically in the GetUsers function of the /onvif/Device component, leading to information disclosure via ONVIF. The vulnerability has a CVSS score of 5.5 and is classified as MEDIUM severity. The attack can be executed remotely, and the exploit is now public. Defenders should assess their exposure, verify affected syste [truncated]