{"id":"CVE-2026-81321","published":"2026-09-18T17:17:01.953","lastModified":"2026-09-19T15:17:02.830","description":"CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An attacker who obtains filesystem access through physical access, a debugging interface, or another vulnerability could recover the configured network identifier and pre-shared key.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-312"],"vendors":[],"products":[],"references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-258-08.json","tags":[]},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-08","tags":[]}],"exploitRefs":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-258-08.json","tags":[]}],"hasPoc":true,"ai":{"summary":"The CM2507 IP cameras store wireless network credentials in cleartext, allowing an attacker with filesystem access to recover sensitive information. This flaw is critical as it can lead to unauthorized network access.","exploitability":"Exploitation is relatively straightforward for an attacker who has gained filesystem access, which can be achieved through physical access or other vulnerabilities.","blast_radius":"If exploited, the attacker could gain full control over the network, leading to potential data breaches and unauthorized network access.","remediation":"Disable the feature that stores wireless network credentials in cleartext or upgrade to a version that addresses this vulnerability, such as 'Upgrade to 2.590 or later'.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["wireless","cleartext","filesystem","network","access"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T09:02:08.578Z"}}