Four Brickcom camera models are sitting wide open, with CISA issuing an advisory covering two vulnerabilities that together let anyone on the network watch live video or take administrative control without logging in.
The affected devices — Cube, Dome, Bullet, and Box, all running firmware version 3.2.3.5.6 — carry a pair of textbook flaws. The first (CVE-2026-50245) lets unauthenticated users pull still images through the /ONVIF endpoint, no credentials required. The second (CVE-2026-50005) is the older and more embarrassing problem: the cameras ship with default credentials that any attacker can use to silently access feeds. Both vulnerabilities score 8.3 (High) under CVSS 4.0. These cameras are deployed across commercial facilities, healthcare settings, financial services, and critical manufacturing — sectors where unauthorized visual access carries real consequences.
What makes the advisory notable is the vendor's posture: Brickcom did not respond to CISA's coordination request. That leaves operators with no patch, no timeline, and guidance that amounts to "call the vendor and hope." CISA's own recommended workaround is network isolation and VPN-gating — reasonable advice, but it does nothing for cameras already internet-exposed.
Default credentials on security cameras is a problem as old as the IP camera market itself — the Mirai botnet in 2016 swept up hundreds of thousands of devices using exactly this technique. A decade later, firmware shipping with unchangeable or unchanged defaults is still apparently standard practice for some manufacturers. If your physical security system runs on network cameras, the question worth asking is not whether Brickcom is on your floor plan, but whether you have ever checked.
