Impact
The vulnerability allows an attacker who gains filesystem access to read wireless network credentials that are stored in cleartext on the device’s storage. The attacker can recover the SSID and pre‑shared key, enabling association to the target network and potential further compromise. The weakness is a cleartext storage issue (CWE-312).
Affected Systems
CareCam HMT.CM2507 IP cameras running the indicated firmware. No additional vendor or product versions are listed, but all devices of this model are affected.
Risk and Exploitability
The CVSS score of 9.3 classifies this as critical, indicating a high impact if exploited. The EPSS score is < 1%, and the vulnerability is not included in CISA’s KEV catalogue, suggesting no documented exploitation yet. The likely attack vector requires the attacker to obtain filesystem access through physical means, a debugging interface, or another existing flaw in the device. Because physical access to IoT cameras is generally limited, the risk is moderate to high, depending on the security controls in place around the cameras and physical environment.
OpenCVE Enrichment