CVE-2026-50005 Details
Description
Brickcom cameras ship with default credentials that allows any unauthenticated remote attacker to silently access camera feeds.
A vulnerability exists in Brickcom cameras that ship with default credentials, enabling any unauthenticated remote attacker to silently access live camera feeds. This issue affects Brickcom Cube, Dome, Bullet, and Box models, all running version 3.2.3.5.6. Successful exploitation could also allow the attacker to retrieve sensitive visual information from the affected premises and gain administrative control of the device.
Brickcom has not responded to CISA's request for coordination. Users are encouraged to contact Brickcom for support through their Help Desk.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 11, 2026CISA-ADP
Assessed Jun 12, 2026CNA
Assessed Jan 1, 1References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-162-03.json | [email protected] | AdvisoryBundleRemedy |
| https://www.brickcom.com/case/ | [email protected] | Permission RequiredVendor |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-162-03 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1392 | Use of Default Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Brickcom Cube | 3.2.3.5.6 |
CPE
Remediation
| |
| Brickcom Dome | 3.2.3.5.6 |
CPE
Remediation
| |
| Brickcom Bullet | 3.2.3.5.6 |
CPE
Remediation
| |
| Brickcom Box | 3.2.3.5.6 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 11, 2026 | New CVE Received | [email protected] |
Volerion