rootpwn

high · CVSS v3 6.8 · CVSS v4 7 · EPSS 0.00196

CVE-2026-81305

CM2507 IP cameras automatically execute predetermined scripts from removable media without validating their authenticity or integrity. This

Overview

CM2507 IP cameras automatically execute predetermined scripts from removable media without validating their authenticity or integrity. This vulnerability allows individuals with physical access to execute arbitrary code within the device's security context. It matters because compromise of physical surveillance hardware can lead to local privilege escalation and unauthorized device control.

Description

CM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity or integrity. An attacker with physical access to the device could supply a malicious script and execute arbitrary code in the security context of the affected device.

Impact

The impact affects Integrity, Availability, and to some extent Confidentiality, as arbitrary code execution under the device security context grants full control over the affected hardware. Attackers with physical access to the camera are directly impacted by this flaw, potentially enabling them to disable monitoring, extract local configurations, or pivot to connected internal network segments. Organizations relying on these cameras for physical security or perimeter surveillance face a risk of localized disruption and surveillance compromise.

Remediation

Apply the latest vendor-supplied firmware update that introduces signature verification for removable media scripts. Disable or restrict physical access to the camera's external media ports where feasible. Implement physical security controls such as locked housings to prevent unauthorized insertion of removable media.

Risk context

The vulnerability is rated as High severity with a CVSS v3 score of 6.8 and CVSS v4 score of 7.0, indicating significant potential impact if exploited. However, the EPSS score of 0.00196 suggests a very low probability of widespread exploitation in the wild, largely constrained by the requirement for physical access.

Affected products

  • CM2507 IP camera

Scores

Severity
high
CVSS v2
7.2
CVSS v3
6.8
CVSS v4
7
EPSS
0.00196

IoT Security Physical Access Arbitrary Code Execution IP Camera Input Validation

← All CVEs