CVE-2026-81321: CareCam CM2507 Cleartext Storage of Sensitive Information
Published Sep 18, 2026
·Updated
CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An attacker who obtains filesystem access through physical access, a debugging interface, or another vulnerability could recover the configured network identifier and pre-shared key.
Affected Software
1 affected component
CareCam CM2507 IP cameras
Event History
Sep 18, 2026
CVE Published
via MITRE·04:22 PM
Data Sourced
via MITRE·04:22 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does this weakness by itself provide an attacker with filesystem access to the camera?
The available information does not establish that it does. Credential recovery requires the attacker to first obtain filesystem access, such as through physical access, a debugging interface, or another vulnerability.
2
What information could be exposed if the device filesystem is accessed?
An attacker could recover the configured wireless network identifier and pre-shared key. This could expose the Wi-Fi credentials configured on the affected camera.