CVE-2026-9274

This vulnerability exists in CP Plus Wi-Fi Camera due to improper protection of sensitive information in runtime memory. An attacker with physical access could exploit this vulnerability by accessing the UART interface and performing memory extraction to obtain sensitive information, including cryptographic private keys, Wi-Fi credentials and configuration data stored in RAM of the targeted device. Successful exploitation of this vulnerability could allow unauthorized access to encrypted communications and connected wireless network of the targeted device.
CVSS

No CVSS.

Configurations

No configuration.

History

23 Jul 2026, 11:10

Type Values Removed Values Added
Summary
  • (es) Esta vulnerabilidad existe en la Cámara Wi-Fi CP Plus debido a una protección inadecuada de información sensible en la memoria en tiempo de ejecución. Un atacante con acceso físico podría explotar esta vulnerabilidad al acceder a la interfaz UART y realizar una extracción de memoria para obtener información sensible, incluyendo claves privadas criptográficas, credenciales de Wi-Fi y datos de configuración almacenados en la RAM del dispositivo objetivo. La explotación exitosa de esta vulnerabilidad podría permitir el acceso no autorizado a comunicaciones cifradas y a la red inalámbrica conectada del dispositivo objetivo.

25 May 2026, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-25 10:16

Updated : 2026-07-23 11:10


NVD link : CVE-2026-9274

Mitre link : CVE-2026-9274

CVE.ORG link : CVE-2026-9274


JSON object : View

Products Affected

No product.

CWE
CWE-312

Cleartext Storage of Sensitive Information