CVE-2026-81321: Carecam hmt.cm2507 Firmware
Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.
CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An attacker who obtains filesystem access through physical access, a debugging interface, or another vulnerability could recover the configured network identifier and pre-shared key.
Affected products
- Carecam hmt.cm2507 Firmware: version v251211.1507 only
Published 2026-09-18. Last modified 2026-09-19.