CVE-2026-50245 PUBLISHED

Brickcom Cameras Missing Authentication for Critical Function

Assigner: icscert
Reserved: 08.06.2026 Published: 11.06.2026 Updated: 12.06.2026

Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no authentication is required to retrieve still images from the camera feed.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N
CVSS Score: 8.3

Product Status

Vendor Brickcom
Product Cube
Versions Default: unaffected
  • Version 3.2.3.5.6 is affected
Vendor Brickcom
Product Dome
Versions Default: unaffected
  • Version 3.2.3.5.6 is affected
Vendor Brickcom
Product Bullet
Versions Default: unaffected
  • Version 3.2.3.5.6 is affected
Vendor Brickcom
Product Box
Versions Default: unaffected
  • Version 3.2.3.5.6 is affected

Workarounds

Brickcom did not respond to CISAs request for coordination. Users are encouraged to reach out to Brickcom for support: https://www.brickcom.com/case/

Credits

  • CISA discovered the PoCs (Proof of Concept) as authored by parsa rezaie khiabanloo. finder

References

Problem Types

  • CWE-306 Missing authentication for critical function CWE