Junglewise Threat Intelligence

CVE-2026-81321: CareCam CM2507 cleartext storage of wireless credentials

CVE-2026-81321 · Severity: critical · CVSS 9.8 · Published 2026-09-18

Technologies: CareCam CM2507. Vendors: CareCam.

Executive brief

CareCam CM2507 IP cameras, used for surveillance in commercial facilities worldwide, store WiFi network credentials in plain text on the device. An attacker with physical access or who exploits other vulnerabilities to reach the device's filesystem could extract the WiFi password and gain access to the camera's network, leading to unauthorized surveillance and lateral network access.

Technical details

The CM2507 stores configured wireless SSID and pre-shared key credentials in cleartext in the device filesystem without encryption. An attacker must first obtain filesystem access through physical access, exploitation of a debugging interface, or chaining with another vulnerability; once gained, credential recovery is trivial, enabling network compromise and potential lateral movement.

Affected products

  • CareCam CM2507 HMT.CM2507 Firmware v251211.1507

Timeline

  • 2026-09-15: disclosed
  • 2026-09-18: advisory

References

Related threats