ZeroHour

CVE-2026-82563

Camera Impersonation Flaw Enables Man-in-the-Middle and Status Manipulation

CVSS 4.0
8.4 high
EPSS
<1%p4
Published
()
Modified
AI analysis

CVE-2026-82563 is an authentication bypass by spoofing (CWE-290) in the communication between an affected camera and its client application, assigned by CISA ICS-CERT, in which the camera's identity is not properly verified. An attacker positioned on an adjacent network segment who obtains user interaction during a camera session can impersonate the camera and insert themselves into a man-in-the-middle or device-emulation position. From there, the attacker can manipulate device status responses, observe the application's requests, and potentially trigger firmware-update behavior, producing high confidentiality and integrity impact on the vulnerable system with only low availability impact. Organizations running the affected camera with its companion application — particularly on flat or shared network segments where adjacent access is feasible — are affected, though the specific vendor, product, and version ranges have not been published in the available data. No exploitation is currently known: the flaw is not listed in CISA KEV and no public proof-of-concept exists.

What to do: Monitor for the forthcoming CISA ICS-CERT advisory and vendor release notes for CVE-2026-82563 to identify the affected product and firmware versions, then apply the vendor patch as soon as it is available. Until patched, keep the camera and its client application on trusted, segmented network segments and avoid initiating camera sessions from untrusted networks (e.g., guest or public Wi-Fi), since exploitation requires adjacent network access plus user interaction. With no public PoC or known in-the-wild exploitation, emergency response is not required, but review any vendor guidance on securing or disabling automatic firmware-update behavior triggered through the application.

Affected
Camera and its companion/client application
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emulation position. This permits manipulation of device status responses, observation of application requests, and potential triggering of firmware-update behavior.

Weakness
CWE-290
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.