CVE-2026-81321

Summary

CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An attacker who obtains filesystem access through physical access, a debugging interface, or another vulnerability could recover the configured network identifier and pre-shared key.

Affected Software

VendorProductVersion RangeStatus
CareCamHMT.CM2507 Firmwarev251211.1507affected

Weaknesses

  • CWE-312: CWE-312

Workarounds

CareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information.

References