CVE-2026-65893 PUBLISHED

Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera

Assigner: CERT-In
Reserved: 23.07.2026 Published: 27.07.2026 Updated: 27.07.2026

This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware.

An attacker with physical access could exploit this vulnerability by placing arbitrary code on removable media and triggering their execution through the debug mechanism.

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code with elevated privileges on the targeted device.

Metrics

CVSS Vector: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7

Product Status

Vendor CP-Plus
Product EZ-P21 IP Camera
Versions Default: unaffected
  • Version version v4.8.8.1 and prior is affected

Solutions

Upgrade CP PLUS EZ-P21 IP Camera to latest firmware version 4.8.16.1 through OTA.

Credits

  • This vulnerability is reported by a team of security researchers including Isukapalli Venkata Mythreya Kumara Sarma, Tiyyagura Venkata Shesha Shaina Reddy and Naga Venkatesh Durga Sai Krishna from Vignan University. Vishwa V and Sathya Priya S from SRMIST Ramapuram. Deven Lunkad and S. Venkatesan from IIIT Allahabad. finder

References

Problem Types

  • CWE-489 Active debug code CWE

Impacts

  • CAPEC-549 Local Execution of Code