CVE-2026-50245

HIGH

Brickcom Cameras Missing Authentication for Critical Function

Title source: cna
STIX 2.1

Description

Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no authentication is required to retrieve still images from the camera feed.

Scores

CVSS v3 7.7
EPSS 0.0016
EPSS Percentile 5.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-306
Status published
Products (4)
Brickcom/Box 3.2.3.5.6
Brickcom/Bullet 3.2.3.5.6
Brickcom/Cube 3.2.3.5.6
Brickcom/Dome 3.2.3.5.6
Published Jun 11, 2026
Tracked Since Jun 12, 2026