Brickcom Cameras
CISA warned that Brickcom camera flaws could expose live video and admin access on affected devices.
Intelligence analysis by GPT-5.4 Mini
CISA issued an ICS advisory for Brickcom cameras after finding two high-severity weaknesses: unauthenticated snapshot access and default credentials. The agency says the issues affect several camera models and urges network isolation and stronger remote-access controls.
CISA found bugs in some Brickcom cameras that could let strangers peek at video or even take control of the camera. It is like leaving a building's security room door open and also using the factory default lock code.
Analysis
What CISA found
CISA published an advisory for Brickcom camera models including Cube, Dome, Bullet, and Box version 3.2.3.5.6. The advisory says successful exploitation could let an attacker access live video feeds, retrieve sensitive visual information from affected premises, and obtain administrative control of the device.
The two flaws
The first issue, CVE-2026-50245, is described as missing authentication for a critical function. CISA says the affected product allows unauthenticated access to live snapshot images through the /ONVIF endpoint, with no authentication required to retrieve still images from the camera feed.
The second issue, CVE-2026-50005, involves default credentials. CISA says the affected product ships with credentials that allow an unauthenticated remote attacker to silently access camera feeds.
Scope and severity
CISA lists the affected sectors as Commercial Facilities, Critical Manufacturing, Financial Services, and Healthcare and Public Health. The advisory says the devices are deployed worldwide and identifies Brickcom as headquartered in Taiwan. Both issues are rated high severity, with CVSS 3.1 base scores of 7.7 and CVSS 4.0 base scores of 8.3.
Response and mitigation
CISA says Brickcom did not respond to its request for coordination. The agency recommends minimizing network exposure, placing control-system networks and remote devices behind firewalls, and using more secure remote access methods such as VPNs when needed. It also reminds organizations to do impact analysis and risk assessment before deploying defensive measures.
CISA notes that no known public exploitation specifically targeting these vulnerabilities has been reported at the time of publication.
Key points
- CISA issued an advisory for Brickcom cameras on June 11, 2026.
- The advisory covers Cube, Dome, Bullet, and Box models running version 3.2.3.5.6.
- One flaw allows unauthenticated access to snapshot images through the `/ONVIF` endpoint.
- A second flaw involves default credentials that can expose camera feeds.
- CISA says no known public exploitation has been reported yet.
If organizations act on the advisory, they can reduce exposure by keeping camera networks segmented and harder to reach. Using stronger remote access and better defensive controls could limit how much harm these flaws can cause.
If the cameras stay exposed or keep default credentials, attackers could view sensitive scenes or control the devices. In sectors that rely on camera surveillance, that could undermine physical security and create a path into broader networks.



