Cleartext Credential Storage Vulnerability in CM2507 IP Cameras
CVE-2026-81321
9.3CRITICAL
What is CVE-2026-81321?
The vulnerability allows the CM2507 IP cameras to store sensitive wireless network credentials in cleartext within the device's filesystem. This design oversight could enable an attacker with physical access or through other vulnerabilities to retrieve the network identifier and pre-shared key, potentially compromising the wireless network's integrity. As a result, unauthorized users could gain access to sensitive data and services connected to the network. It is crucial for users and organizations relying on these devices to assess their security measures and implement safeguards against unauthorized access.
Affected Version(s)
HMT.CM2507 Firmware v251211.1507
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ben Law reported this vulnerability to CISA.
