← Back to search

CVE-2026-81321

9.8 CRITICALpublic exploit available

Published 2026-09-18 · Updated 2026-09-19

AI risk analysis

Summary
The CM2507 IP cameras store wireless network credentials in cleartext, allowing an attacker with filesystem access to recover sensitive information. This flaw is critical as it can lead to unauthorized network access.
Exploitability
Exploitation is relatively straightforward for an attacker who has gained filesystem access, which can be achieved through physical access or other vulnerabilities.
Blast radius
If exploited, the attacker could gain full control over the network, leading to potential data breaches and unauthorized network access.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the feature that stores wireless network credentials in cleartext or upgrade to a version that addresses this vulnerability, such as 'Upgrade to 2.590 or later'.
wirelesscleartextfilesystemnetworkaccess

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An attacker who obtains filesystem access through physical access, a debugging interface, or another vulnerability could recover the configured network identifier and pre-shared key.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-312

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.