CVE-2024-58330
A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytic
CVSS
7.5
High
EPSS
0.5%
p40
KEV
—
Exploit Today
12
0-100
Published: Jul 23, 2026 · Last modified: Jul 23, 2026 · CWE-284
Not enough EPSS history yet.
A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-65758——
——0The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions.7hCVE-2026-65757—2.8%
——1The editor popup could expose restricted module data to authenticated users without the required module permissions or valid request tokens.7hCVE-2026-64876—2.8%
——1Database-update requests lacked consistent token and Super User checks, this could cause unauthorized updates.7hCVE-2026-64871—2.8%
——1Administrator URL purges did not consistently require a valid token and cache-management permission.7hCVE-2026-64796—9.0%
——3Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection.20hCVE-2026-64794—13.9%
——4User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content could expose authentication-related data, raw user parameters or restricted contact details.20h