Sceawere

Vulnerability Detail

CVE-2026-100906UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Eyeplus ONVIF Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
4h ago
Vendor
n/a
Product
Eyeplus
Attack Type
Information Disclosure
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was detected in Eyeplus 57.0.0.0308. The affected element is the function GetUsers of the file /onvif/Device of the component ONVIF. The manipulation results in information disclosure. The attack can be executed remotely. The exploit is now public and may be used.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-09-28T04:17:08.120Z",
  "pubdate": "2026-09-28T04:17:08.120Z",
  "executiveSummary": "A critical information disclosure vulnerability has been identified within the Eyeplus 57.0.0.0308 surveillance firmware.\nThe vulnerability resides within the ONVIF component, specifically affecting the GetUsers function located at /onvif/Device.\nThis flaw allows remote, unauthenticated attackers to query sensitive user information, posing significant security risks to the confidentiality and integrity of the device management system.\nAs the exploit is currently public, the attack surface is active and presents a high risk of exploitation for unauthorized reconnaissance or credential harvesting.\nSuccessful exploitation facilitates unauthorized access to account details, enabling potential escalation of privileges or broader unauthorized access to the affected surveillance infrastructure.",
  "technicalDetails": "The vulnerability is localized within the ONVIF protocol implementation in Eyeplus version 57.0.0.0308. The specific endpoint, /onvif/Device, exposes an insecure implementation of the GetUsers function.\nUnder normal protocol operations, the GetUsers function is intended to retrieve information about system users. In this vulnerable implementation, the endpoint fails to properly enforce mandatory authentication mechanisms or authorization controls required by the ONVIF specification.\nAn unauthenticated remote attacker can craft an ONVIF-compliant SOAP request targeting the /onvif/Device service. By invoking the GetUsers method, the attacker can bypass access control checks that should restrict this function to administrators only.\nThe root cause is a deficiency in input validation and access control logic within the device's web services stack, which fails to validate the request origin or session tokens before processing the enumeration of user accounts.\nThe attack flow proceeds as follows: First, the attacker identifies a network-exposed Eyeplus device supporting ONVIF. Second, the attacker sends an unauthenticated XML-formatted SOAP request to the /onvif/Device endpoint. Third, the device's backend logic processes the request and returns the full list of users, including sensitive identifiers and account metadata, in the server response.\nBecause this vulnerability allows for the programmatic extraction of user metadata, it facilitates reconnaissance for further attacks, such as brute-force or credential stuffing attempts targeting the discovered accounts.\nThe lack of integrity or confidentiality constraints during the execution of this function allows any remote actor with network visibility to the device to extract system configuration details that would otherwise be restricted to authenticated administrative sessions.\nThis exposure is critical, as it effectively nullifies the authentication perimeter of the device's ONVIF management interface, enabling passive discovery of administrative account information without triggering typical authentication failure alerts."
}
CVE-2026-100906: Eyeplus ONVIF Information Disclosure (MEDIUM Severity, CVSS: 5.3) | Sceawere