CVE-2026-50245
Received Received - Intake
Unauthenticated Access to Live Snapshots in Brickcom Cameras

Publication date: 2026-06-11

Last updated on: 2026-06-11

Assigner: ICS-CERT

Description
Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no authentication is required to retrieve still images from the camera feed.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-11
Last Modified
2026-06-11
Generated
2026-06-12
AI Q&A
2026-06-12
EPSS Evaluated
N/A
NVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability affects Brickcom cameras by allowing unauthenticated users to access live snapshot images through the /ONVIF endpoint.

No authentication is required to retrieve still images from the camera feed, which means anyone can view these images without permission.

Impact Analysis

The vulnerability can lead to unauthorized access to live images from the affected cameras.

This could result in privacy violations, exposure of sensitive or confidential information, and potential security risks if the camera feed is used for surveillance.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50245. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart