{"id":"CVE-2026-81305","published":"2026-09-18T16:17:10.103","lastModified":"2026-09-19T15:17:02.673","description":"CM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity or integrity. An attacker with physical access to the device could supply a malicious script and execute arbitrary code in the security context of the affected device.","cvssScore":6.8,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-829"],"vendors":[],"products":[],"references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-258-08.json","tags":[]},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-08","tags":[]}],"exploitRefs":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-258-08.json","tags":[]}],"hasPoc":true,"ai":null}