Sensitive Information Disclosure in CP Plus Wi-Fi Camera
CVE-2026-9274

5.2MEDIUM

What is CVE-2026-9274?

The vulnerability in CP Plus Wi-Fi Camera arises from inadequate protection of sensitive information stored in the device's runtime memory. An attacker with physical access to the device can potentially exploit this flaw by connecting to the UART interface to extract critical data, including cryptographic private keys, Wi-Fi credentials, and other configuration details directly from the RAM. The successful execution of this attack could lead to unauthorized access to encrypted communications and the connected wireless network, putting sensitive information at significant risk.

Affected Version(s)

Wi-Fi Camera CP-E38Q, CP-E48Q, CP-E25Q, CP-E35Q, CP-E45Q, CP-E28Q, CP-E21Q, CP-E31Q, CP-E41Q, CP-E24Q, CP-Z43Q, CP-E34Q, CP-E44Q, CP-T31Q, CP-V48Q, CP-V41Q, CP-Z45Q v02.21.031 or below

References

CVSS V4

Score:
5.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability is reported by Mohsin Quresh.
.