CVE-2026-100907
Received Received - Intake

Information Disclosure in Eyeplus P2PCam Service

Vulnerability report for CVE-2026-100907, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A flaw has been found in Eyeplus 57.0.0.0308. The impacted element is an unknown function of the file /snapshot of the component p2pcam Service. This manipulation causes information disclosure. The attack is possible to be carried out remotely. The exploit has been published and may be used.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
shenzhen_ningyuanda_technology eyeplus 57.0.0.0308
shenzhen_ningyuanda_technology ycc365_plus 57.0.0.0308

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an information disclosure flaw in Eyeplus 57.0.0.0308 where an exposed HTTP snapshot endpoint on TCP port 8001 allows attackers on the local network to retrieve a JPEG image of the camera's current video frame without authentication. The attack is remote and can be exploited by sending an unauthenticated HTTP GET request to /snapshot.

Detection Guidance

To detect this vulnerability, check if your Eyeplus or YCC365 Plus camera has an exposed HTTP snapshot endpoint on TCP port 8001. Send an unauthenticated HTTP GET request to the camera's IP address on port 8001 with the path /snapshot. If a valid JPEG image is returned, the device is vulnerable.

Impact Analysis

This vulnerability allows attackers to capture live images from the camera without authentication, enabling periodic surveillance without establishing an RTSP session. This poses significant privacy risks as sensitive visual data can be accessed remotely.

Compliance Impact

This vulnerability allows unauthorized access to live camera snapshots without authentication, which could lead to unauthorized collection of personal or sensitive data. This may violate GDPR's data protection principles if personal data is captured, and HIPAA's safeguards for protected health information if such data is exposed.

Mitigation Strategies

Immediately restrict access to port 8001 on the camera by blocking it at the network firewall. Update the camera firmware to the latest version if an official patch is available. Disable unnecessary services like unauthenticated RTSP streaming if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100907. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart