Cleartext Credential Storage Vulnerability in CM2507 IP Cameras
CVE-2026-81321

9.3CRITICAL

Key Information:

Vendor

Carecam

Vendor
CVE Published:
18 September 2026

What is CVE-2026-81321?

The vulnerability allows the CM2507 IP cameras to store sensitive wireless network credentials in cleartext within the device's filesystem. This design oversight could enable an attacker with physical access or through other vulnerabilities to retrieve the network identifier and pre-shared key, potentially compromising the wireless network's integrity. As a result, unauthorized users could gain access to sensitive data and services connected to the network. It is crucial for users and organizations relying on these devices to assess their security measures and implement safeguards against unauthorized access.

Affected Version(s)

HMT.CM2507 Firmware v251211.1507

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ben Law reported this vulnerability to CISA.
.