CVE-2026-100908
Received Received - Intake

Stack-Based Buffer Overflow in Eyeplus p2pcam HTTP Parser

Vulnerability report for CVE-2026-100908, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A vulnerability has been found in Eyeplus 57.0.0.0308. This affects an unknown function of the component p2pcam HTTP Parser. Such manipulation leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
eyeplus ip_camera 57.0.0.0308

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
CWE-119 The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stack-based buffer overflow in the p2pcam HTTP parser of Eyeplus IP Camera firmware version 57.0.0.0308. An attacker can send a crafted GET request with an excessively long URI path (1024 bytes or more) to port 8001, causing the camera's p2pcam HTTP service to crash or become unresponsive. This disrupts all network services on the device, including video, ONVIF, RTSP, and P2P services, for about one minute before the device recovers.

Detection Guidance

To detect this vulnerability, monitor network traffic for unusually long HTTP GET requests targeting port 8001 on Eyeplus IP cameras. Use packet capture tools like tcpdump or Wireshark to inspect URI lengths. Example command: tcpdump -i eth0 -A port 8001 | grep -E 'GET /.{1024,}'

Check for repeated crashes or unresponsiveness in the p2pcam HTTP service. Logs may show stack overflow errors. Verify firmware version matches 57.0.0.0308.

Impact Analysis

This vulnerability allows an unauthenticated attacker on the local network to temporarily disable all camera services, including video streaming, remote access, and surveillance capabilities. The device becomes unresponsive for approximately one minute, causing a loss of monitoring and remote access during that period.

Compliance Impact

This vulnerability causes temporary disruption of surveillance and remote access services due to a stack-based buffer overflow in the p2pcam HTTP parser. While it does not lead to confirmed remote code execution, the resulting Denial of Service (DoS) could impact data availability and integrity, potentially violating compliance requirements for continuous monitoring and data access under standards like GDPR and HIPAA.

Mitigation Strategies

Isolate affected cameras from critical networks. Block or restrict access to port 8001 at the firewall level. Update firmware if a patch is available. Monitor for unusual traffic patterns.

Consider disabling unnecessary services like ONVIF or RTSP temporarily until mitigation is confirmed. Contact Eyeplus support for official patches or workarounds.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100908. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart