# Brickcom Cameras Exposed: Unpatched Authentication Flaws Threaten Critical Infrastructure Worldwide


## The Threat


Two critical authentication vulnerabilities affecting Brickcom network cameras have exposed live video feeds and administrative access to unauthenticated attackers worldwide. The flaws—one allowing direct snapshot retrieval without credentials and another exploiting default credentials—affect four widely deployed camera models used in hospitals, financial institutions, manufacturing facilities, and commercial buildings globally.


The vulnerabilities represent a textbook case of authentication negligence: CVE-2026-50245 allows attackers to bypass authentication entirely and access live snapshot images through the /ONVIF endpoint, while CVE-2026-50005 enables remote access using hardcoded factory credentials. An attacker need only know the camera's IP address to gain unauthorized visual access to sensitive premises, retrieve intelligence about physical operations, or pivot into the device for administrative control.


Security researchers have already published proof-of-concept exploits, meaning the technical barriers to exploitation are minimal. Brickcom's parent company has not responded to CISA's coordination request, leaving affected organizations with no official patch and a vendor that appears either unwilling or unable to address the issue. For critical infrastructure operators—particularly in healthcare and financial services—this represents an immediate security gap with no apparent remediation timeline.


## Severity and Impact


| Attribute | Details |

|-----------|---------|

| CVE Identifiers | CVE-2026-50245, CVE-2026-50005 |

| CVSS 3.1 Score | 7.7 (HIGH) |

| CVSS 4.0 Score | 8.3 (HIGH) |

| Vector (v3.1) | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |

| Vector (v4.0) | CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N |

| Related CWE | CWE-306 (Missing Authentication for Critical Function), CWE-1392 (Use of Default Credentials) |

| Attack Complexity | Low — no special conditions required |

| Authentication Required | None |

| User Interaction | None |

| Impact | Confidentiality: High, Integrity: High |


## Affected Products


Brickcom camera models running version 3.2.3.5.6 are confirmed vulnerable:


  • Brickcom Cube (v3.2.3.5.6)
  • Brickcom Dome (v3.2.3.5.6)
  • Brickcom Bullet (v3.2.3.5.6)
  • Brickcom Box (v3.2.3.5.6)

  • The company is headquartered in Taiwan and has deployed cameras globally across critical infrastructure sectors including healthcare facilities, financial institutions, manufacturing plants, and commercial office buildings.


    ## Mitigations


    Immediate Actions:


    1. Network Isolation: Remove affected Brickcom cameras from internet-facing networks immediately. Relocate them behind firewalls and ensure they are not accessible from the public internet or untrusted networks.


    2. Change Credentials: If cameras remain in use and cannot be isolated, change default credentials to strong, unique passwords. However, this does not mitigate CVE-2026-50245's unauthenticated snapshot access.


    3. Access Control: Implement strict network segmentation between camera networks and critical business systems. Use VLANs or network access controls to limit what systems can communicate with the cameras.


    4. Vendor Contact: Reach out to Brickcom support at https://www.brickcom.com/case/ to request patches, timelines, or alternative remediation guidance. Given vendor non-responsiveness to CISA, response may be limited.


    5. Device Audit: Inventory all Brickcom cameras across your organization and verify which firmware versions are deployed. Check for any unauthorized access logs or unusual activity.


    6. Compensating Controls: Until patches are available, require VPN access for all remote administration of cameras and disable the /ONVIF endpoint if not critical to operations.


    ## References


  • CISA Alert: [Brickcom Cameras Vulnerabilities](https://www.cisa.gov/news-events/alerts)
  • Vendor Support Page: https://www.brickcom.com/case/
  • CVSS Calculator: https://www.first.org/cvss/calculator/3.1
  • CWE-306 (Missing Authentication): https://cwe.mitre.org/data/definitions/306.html
  • CWE-1392 (Default Credentials): https://cwe.mitre.org/data/definitions/1392.html

  • ---


    ## HackWire Analysis


    What makes this vulnerability notably dangerous is not the technical novelty—dual authentication failures are predictable in poorly developed firmware—but the vendor's apparent abandonment of the product. CISA's statement that "Brickcom did not respond to CISA's request for coordination" is rare candor from federal advisories, and it signals a critical problem: no patch is coming.


    This creates an asymmetric situation for defenders. Organizations cannot simply wait for a firmware update from the vendor. They must immediately assume Brickcom cameras are compromised and treat them as untrusted devices. For healthcare facilities using these cameras to monitor patient areas, operating rooms, or medication storage, the exposure is particularly acute—live feeds could reveal medical procedures, patient identities, or operational vulnerabilities that expose patient safety.


    The presence of public proof-of-concept code amplifies the threat. Opportunistic threat actors and automated scanning now have turnkey methods to identify and exploit these cameras. Financial institutions using Brickcom equipment for branch security face potential reconnaissance attacks before physical theft or fraud. Manufacturing plants could be surveilled for security protocols, high-value inventory, or production bottlenecks.


    What's notable in the broader landscape: this is emblematic of IoT security's structural weakness. Vendors ship cameras with factory credentials and minimal authentication logic, then deprioritize security updates once the product is in the field. Organizations treating network cameras as optional perimeter devices rather than critical infrastructure components often discover these flaws only after compromise.


    The immediate lesson for critical infrastructure operators: assume all legacy IP camera deployments are vulnerable to similar flaws. Conduct a security audit of camera inventory, prioritize network isolation of anything non-essential, and treat video feeds as sensitive as the facilities they monitor. — *HackWire Editorial*


    ## Related Coverage


  • Read more in our [Policy](https://www.hackwire.news/category/policy) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)