CVE-2023-39509: Bosch CPP13 Firmware

High severity, CVSS 7.2. EPSS: 1.5% chance of exploitation in the next 30 days.

A command injection vulnerability exists in Bosch IP cameras that allows an authenticated user with administrative rights to run arbitrary commands on the OS of the camera.

Affected products

  • Bosch CPP13 Firmware: up to and including 8.90
  • Bosch CPP14 Firmware: from 8.20, up to and including 8.81

Published 2023-12-18. Last modified 2026-06-17.