CVE-2026-65893
Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware. An attacker with physical access could exploit this vulnerability by placing arbitrary code on removable media and triggering their execution through the debug mechanism. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code with elevated privileges on the targeted device.
| CWE | CWE-489 |
| Vendor | cp-plus |
| Product | ez-p21 ip camera |
| Published | Jul 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for cp-plus ez-p21 ip camera
Be the first to know when new unknown vulnerabilities affecting cp-plus ez-p21 ip camera are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
CP-Plus / EZ-P21 IP Camera
version v4.8.8.1 and prior
References
Credits
This vulnerability is reported by a team of security researchers including Isukapalli Venkata Mythreya Kumara Sarma, Tiyyagura Venkata Shesha Shaina Reddy and Naga Venkatesh Durga Sai Krishna from Vignan University. Vishwa V and Sathya Priya S from SRMIST Ramapuram. Deven Lunkad and S. Venkatesan from IIIT Allahabad.