CVE-2026-9274 Details
Description
This vulnerability exists in CP Plus Wi-Fi Camera due to improper protection of sensitive information in runtime memory. An attacker with physical access could exploit this vulnerability by accessing the UART interface and performing memory extraction to obtain sensitive information, including cryptographic private keys, Wi-Fi credentials and configuration data stored in RAM of the targeted device. Successful exploitation of this vulnerability could allow unauthorized access to encrypted communications and connected wireless network of the targeted device.
A vulnerability exists in CP Plus Wi-Fi Cameras, specifically in the models CP-E38Q, CP-E48Q, CP-E25Q, CP-E35Q, CP-E45Q, CP-E28Q, CP-E21Q, CP-E31Q, CP-E41Q, CP-E24Q, CP-Z43Q, CP-E34Q, CP-E44Q, CP-T31Q, CP-V48Q, CP-V41Q, and CP-Z45Q, all running firmware version v02.21.031 or below. This vulnerability arises from inadequate protection of sensitive information in the device's runtime memory. An attacker with physical access could exploit this issue by accessing the UART interface to perform memory extraction. This exploitation could lead to the retrieval of sensitive data such as cryptographic private keys, Wi-Fi credentials, and configuration information stored in the device's RAM. The successful exploitation of this vulnerability could enable unauthorized access to encrypted communications and the connected wireless network of the affected device.
Users are advised to upgrade their CP Plus Wi-Fi Camera to the latest firmware version v02.21.041. This update can be obtained through over-the-air (OTA) using the Ezykam+ mobile application.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 25, 2026CISA-ADP
Assessed May 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2026-0266 | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-312 | Cleartext Storage of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| CP Plus CP-E38Q | <v02.21.031 (semver) |
CPE
Remediation
| |
| CP Plus CP-E48Q | <v02.21.031 (semver) |
CPE
Remediation
| |
| CP Plus CP-E25Q | <v02.21.031 (semver) |
CPE
Remediation
| |
| CP Plus CP-E35Q | <v02.21.031 (semver) |
CPE
Remediation
| |
| CP Plus CP-E45Q | <v02.21.031 (semver) |
CPE
Remediation
| |
| CP Plus CP-E28Q | <v02.21.031 (semver) |
CPE
Remediation
| |
| CP Plus CP-E21Q | <v02.21.031 (semver) |
CPE
Remediation
| |
| CP Plus CP-E31Q | <v02.21.031 (semver) |
CPE
Remediation
| |
| CP Plus CP-E41Q | <v02.21.031 (semver) |
CPE
Remediation
| |
| CP Plus CP-E24Q | <v02.21.031 (semver) |
CPE
Remediation
| |
| CP Plus CP-Z43Q | <v02.21.031 (semver) |
CPE
Remediation
| |
| CP Plus CP-E34Q | <v02.21.031 (semver) |
CPE
Remediation
| |
| CP Plus CP-E44Q | <v02.21.031 (semver) |
CPE
Remediation
| |
| CP Plus CP-T31Q | <v02.21.031 (semver) |
CPE
Remediation
| |
| CP Plus CP-V48Q | <v02.21.031 (semver) |
CPE
Remediation
| |
| CP Plus CP-V41Q | <v02.21.031 (semver) |
CPE
Remediation
| |
| CP Plus CP-Z45Q | <v02.21.031 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 25, 2026 | New CVE Received | [email protected] |
Volerion