AllCyberNews

CVE-2026-81321

CareCam CM2507 Cleartext Storage of Sensitive Information

CVSS 9.3 critical · CareCam HMT.CM2507 Firmware · published 2026-09-18

CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An attacker who obtains filesystem access through physical access, a debugging interface, or another vulnerability could recover the configured network identifier and pre-shared key.

Coverage 1 source

  1. 2026-09-15 CISA Cybersecurity Advisories high CareCam CM2507

    Multiple vulnerabilities in CareCam CM2507 could allow attackers to access live video, execute code, and modify device operation.

Mentioned with

CVE-2026-81305 CVE-2026-84398 CVE-2026-84400 CVE-2026-85478 CVE-2026-85497 CVE-2026-88259

Also covered