CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An attacker who obtains filesystem access through physical access, a debugging interface, or another vulnerability could recover the configured network identifier and pre-shared key.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
CareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information.
References
History
Fri, 18 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An attacker who obtains filesystem access through physical access, a debugging interface, or another vulnerability could recover the configured network identifier and pre-shared key. | |
| Title | CareCam CM2507 Cleartext Storage of Sensitive Information | |
| Weaknesses | CWE-312 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-09-18T16:22:32.721Z
Reserved: 2026-09-10T15:00:49.622Z
Link: CVE-2026-81321
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses