CVE-2026-9274: CP Plus Wi-Fi Camera CP-e38q, CP-e48q, CP-e25q, CP-e35q, CP-e45q, CP-e28q, CP-e21q, CP-e31q, CP-e41q, CP-e24q, CP-z43q, CP-e34q, CP-e44q, CP-t31q, CP-v48q, CP-v41q, CP-z45q
Medium severity, CVSS 5.2. EPSS: 0.1% chance of exploitation in the next 30 days.
This vulnerability exists in CP Plus Wi-Fi Camera due to improper protection of sensitive information in runtime memory. An attacker with physical access could exploit this vulnerability by accessing the UART interface and performing memory extraction to obtain sensitive information, including cryptographic private keys, Wi-Fi credentials and configuration data stored in RAM of the targeted device. Successful exploitation of this vulnerability could allow unauthorized access to encrypted communications and connected wireless network of the targeted device.
Affected products
- CP Plus Wi-Fi Camera CP-e38q, CP-e48q, CP-e25q, CP-e35q, CP-e45q, CP-e28q, CP-e21q, CP-e31q, CP-e41q, CP-e24q, CP-z43q, CP-e34q, CP-e44q, CP-t31q, CP-v48q, CP-v41q, CP-z45q: up to and including v02.21.031
Published 2026-05-25. Last modified 2026-07-23.