Vulnerability Report

CVE-2026-65893

RCE

Title: CP PLUS EZ-P21 IP Camera Insecure Debug Feature RCE

RCE

Proof Of Concept

PoC Available for CVE-2026-65893

CWE Category CWE-489
Published Date Jul 27, 2026
Modified Date Jul 27, 2026
Exploit Status Available
Score 7.0 CVSS v4.0
Exploit Probability (EPSS)
0.16%

Vulnerability Summary

CVE-2026-65893: This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware. An attacker with physical access could exploit this vulnerability by placing arbitrary code on removable media and triggering their execution through the debug mechanism. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code with elevated privileges on the targeted device.

Impacted Vendors

Analysis in Progress...

Reference Links

CVSS v4.0
Source Entity [email protected]
Severity HIGH
7.0
Attack Vector
PHYSICAL
Complexity
LOW
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
N/A
RAW VECTOR CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2026-65893 Exploits & PoCs (Proof Of Concept)

GitHub https://github.com/CyberVinner/CP-PLUS-EZ-P21-CVE-2026-65893-65894
View Code
GitHub https://github.com/ivmks74/IIITA-IoT-Security-Research
View Code
MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data updated via NVD.

Attack Vector Matrix

Access Vector PHYSICAL
Complexity LOW
Privileges N/A
Interaction NONE
CVSS Vector String CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Affected Stack

No specific products linked.