Script Execution Vulnerability in CM2507 IP Cameras by Unknown Vendor
CVE-2026-81305
7HIGH
What is CVE-2026-81305?
The CM2507 IP cameras contain a critical vulnerability that allows them to execute scripts from removable media automatically. This occurs without validating the authenticity or integrity of the script. An attacker with direct physical access to the camera can introduce a malicious script, leading to unauthorized arbitrary code execution within the device's security context. This poses significant risks as it may lead to unauthorized surveillance or loss of control over the camera.
Affected Version(s)
HMT.CM2507 Firmware v251211.1507
References
CVSS V4
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ben Law reported this vulnerability to CISA.
