CVE-2026-100907 Details
Description
A flaw has been found in Eyeplus 57.0.0.0308. The impacted element is an unknown function of the file /snapshot of the component p2pcam Service. This manipulation causes information disclosure. The attack is possible to be carried out remotely. The exploit has been published and may be used.
A vulnerability exists in the Eyeplus IP camera model EYEPLUS_DEV, specifically in the firmware version 57.0.0.0308. The issue arises from an unauthenticated HTTP snapshot endpoint on TCP port 8001, part of the p2pcam service. This flaw allows remote information disclosure, as an attacker can retrieve a JPEG image of the camera's current video frame with a simple unauthenticated GET request. This vulnerability is separate from the ONVIF snapshot feature available on port 80, which did not function as intended on the tested device.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/devjanger/iot-advisories/blob/main/EYEPLUS-8001-Unauth-Snapshot-Disclosure.md | [email protected] | ExploitTechnical Description |
| https://vuldb.com/cve/CVE-2026-100907 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/919784 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/410858 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/410858/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Eyeplus | 57.0.0.0308 |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion