{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aeyeplusp2pcam/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:eyeplus:p2pcam:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-100908"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["p2pcam (57.0.0.0308)"],"_cs_severities":["low"],"_cs_tags":["vulnerability","rce","buffer-overflow"],"_cs_type":"advisory","_cs_vendors":["Eyeplus"],"content_html":"\u003cp\u003eA stack-based buffer overflow vulnerability (CVE-2026-100908) has been identified in the p2pcam HTTP Parser component of Eyeplus version 57.0.0.0308. The vulnerability originates from improper bounds checking within an unknown function of the parser, allowing a remote attacker to trigger a buffer overflow condition. By sending a maliciously crafted HTTP request, an unauthorized remote actor can overwrite adjacent memory, potentially leading to arbitrary code execution on the target device. Publicly disclosed exploit code for this vulnerability is currently available, significantly lowering the barrier to entry for attackers. Given the nature of the p2pcam component, this risk is particularly acute for Internet-facing surveillance and camera hardware running the affected firmware version.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for unauthenticated remote code execution on the affected device, potentially leading to a complete compromise of the system, data exfiltration, or the recruitment of the device into a botnet. The severity is rated at 7.5 (CVSS v3.1), reflecting the potential for full system control by remote actors.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all internet-facing devices running Eyeplus firmware version 57.0.0.0308.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the p2pcam HTTP interface to trusted internal segments only, as this is a remote-exploitable vulnerability.\u003c/li\u003e\n\u003cli\u003eContact the vendor for a security patch or firmware update addressing CVE-2026-100908.\u003c/li\u003e\n\u003cli\u003eMonitor ingress traffic on ports associated with the p2pcam web interface for anomalous HTTP payloads, specifically looking for abnormally long URI strings or unexpected character sequences.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-28T06:47:04Z","date_published":"2026-09-28T06:47:04Z","id":"https://feed.craftedsignal.io/briefs/2026-09-eyeplus-overflow/","summary":"A stack-based buffer overflow vulnerability in the p2pcam HTTP Parser component of Eyeplus 57.0.0.0308 allows remote attackers to execute arbitrary code via crafted HTTP requests.","title":"Remote Stack-based Buffer Overflow in Eyeplus p2pcam HTTP Parser","url":"https://feed.craftedsignal.io/briefs/2026-09-eyeplus-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:eyeplus:p2pcam:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}