CVE-2026-50245 Details
Description
Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no authentication is required to retrieve still images from the camera feed.
A vulnerability in Brickcom cameras allows unauthorized access to live snapshot images through the ONVIF endpoint, without requiring authentication. This issue affects Brickcom Cube, Dome, Bullet, and Box models, all running version 3.2.3.5.6. The vulnerability could be exploited by remote, unauthenticated attackers to access sensitive visual information from affected premises and potentially gain administrative control of the devices.
Brickcom has not responded to CISA's request for coordination. Users are encouraged to contact Brickcom for support through their Help Desk.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 11, 2026CISA-ADP
Assessed Jun 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-162-03.json | [email protected] | |
| https://www.brickcom.com/case/ | [email protected] | Permission RequiredVendor |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-162-03 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Brickcom Cube | 3.2.3.5.6 |
CPE
Remediation
| |
| Brickcom Dome | 3.2.3.5.6 |
CPE
Remediation
| |
| Brickcom Bullet | 3.2.3.5.6 |
CPE
Remediation
| |
| Brickcom Box | 3.2.3.5.6 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 11, 2026 | New CVE Received | [email protected] |
Volerion