Information Exposure Vulnerability in CP-Plus Wi-Fi Camera
Summary
| CVE | CVE-2026-9274 |
|---|---|
| State | PUBLISHED |
| Assigner | CERT-In |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-25 10:16:15 UTC |
| Updated | 2026-05-26 20:04:56 UTC |
| Description | This vulnerability exists in CP Plus Wi-Fi Camera due to improper protection of sensitive information in runtime memory. An attacker with physical access could exploit this vulnerability by accessing the UART interface and performing memory extraction to obtain sensitive information, including cryptographic private keys, Wi-Fi credentials and configuration data stored in RAM of the targeted device. Successful exploitation of this vulnerability could allow unauthorized access to encrypted communications and connected wireless network of the targeted device. |
Risk And Classification
Primary CVSS: v4.0 5.2 MEDIUM from [email protected]
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.000130000 probability, percentile 0.021460000 (date 2026-05-30)
Problem Types: CWE-312 | CWE-312 CWE-312: Cleartext Storage of Sensitive Information
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 5.2 | MEDIUM | CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:L/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 5.2 | MEDIUM | CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:L/SI:N/SA:N |
CVSS v4.0 Breakdown
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | CP Plus | Wi-Fi Camera CP-E38Q CP-E48Q CP-E25Q CP-E35Q CP-E45Q CP-E28Q CP-E21Q CP-E31Q CP-E41Q CP-E24Q CP-Z43Q CP-E34Q CP-E44Q CP-T31Q CP-V48Q CP-V41Q CP-Z45Q | affected v02.21.031 or below | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.cert-in.org.in/s2cMainServlet | [email protected] | www.cert-in.org.in | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: This vulnerability is reported by Mohsin Quresh. (en)
Additional Advisory Data
Solutions
CNA: Upgrade CP Plus Wi-Fi Camera to the latest firmware version v02.21.041 through OTA using the Ezykam+ mobile application.https://cpplusworld.com/products/ezyhome/ezykam