Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 7epss 0.2%
from disclosure to weapon1 days
Published on NVDJul 27
1st PoC+1d
exploitation probability
0.2%top 95% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware.
An attacker with physical access could exploit this vulnerability by placing arbitrary code on removable media and triggering their execution through the debug mechanism.
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code with elevated privileges on the targeted device.
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
CP-Plus · EZ-P21 IP Camerapublic PoCs found — 2
githubgithub.com/ivmks74/IIITA-IoT-Security-Research★ 0githubgithub.com/CyberVinner/CP-PLUS-EZ-P21-CVE-2026-65893-65894★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.