Executive brief
A security vulnerability in CP Plus Wi-Fi cameras allows an individual with physical access to the device to extract sensitive information from its internal memory. This includes Wi-Fi passwords, configuration data, and encryption keys used to secure communications. An attacker could use this information to intercept video feeds, join the local wireless network, or impersonate the device.
Technical details
The vulnerability (CWE-312) is caused by the improper protection of sensitive data within the device's RAM during runtime. An attacker with physical access can connect to the UART (Universal Asynchronous Receiver-Transmitter) interface on the camera's hardware to perform memory extraction. This process allows for the retrieval of cleartext Wi-Fi credentials, device configuration data, and cryptographic private keys. With these assets, an attacker can decrypt communications, perform Man-in-the-Middle (MITM) attacks, or gain unauthorized access to the local wireless network. The issue affects multiple CP Plus models with firmware version v02.21.031 or below and is addressed in firmware version v02.21.041.
Affected products
- CP Plus CP-E38Q v02.21.031 or below
- CP Plus CP-E48Q v02.21.031 or below
- CP Plus CP-E25Q v02.21.031 or below
- CP Plus CP-E35Q v02.21.031 or below
- CP Plus CP-E45Q v02.21.031 or below
- CP Plus CP-E28Q v02.21.031 or below
- CP Plus CP-E21Q v02.21.031 or below
- CP Plus CP-E31Q v02.21.031 or below
- CP Plus CP-E41Q v02.21.031 or below
- CP Plus CP-E24Q v02.21.031 or below
- CP Plus CP-Z43Q v02.21.031 or below
- CP Plus CP-E34Q v02.21.031 or below
- CP Plus CP-E44Q v02.21.031 or below
- CP Plus CP-T31Q v02.21.031 or below
- CP Plus CP-V48Q v02.21.031 or below
- CP Plus CP-V41Q v02.21.031 or below
- CP Plus CP-Z45Q v02.21.031 or below
Timeline
- 2026-05-25: disclosed: Original advisory date by CERT-In
- 2026-05-25: advisory: NVD publication date
- 2026-05-27: patched: Last updated date indicating solution availability via OTA update