VYPR
Unrated severityNVD Advisory· Published May 25, 2026

Information Exposure Vulnerability in CP-Plus Wi-Fi Camera

CVE-2026-9274

Description

This vulnerability exists in CP Plus Wi-Fi Camera due to improper protection of sensitive information in runtime memory. An attacker with physical access could exploit this vulnerability by accessing the UART interface and performing memory extraction to obtain sensitive information, including cryptographic private keys, Wi-Fi credentials and configuration data stored in RAM of the targeted device.

Successful exploitation of this vulnerability could allow unauthorized access to encrypted communications and connected wireless network of the targeted device.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Physical access to UART on CP Plus Wi-Fi cameras allows memory extraction of cryptographic keys, Wi-Fi credentials, and configuration data.

Vulnerability

This vulnerability exists in CP Plus Wi-Fi Camera due to improper protection of sensitive information in runtime memory. Affected devices include multiple models (CP-E38Q, CP-E48Q, CP-E25Q, CP-E35Q, CP-E28Q, CP-E21Q, CP-E31Q, CP-E41Q, CP-E24Q, CP-Z43Q, CP-E34Q, CP-E44Q, CP-T31Q, CP-V48Q, CP-V41Q, CP-Z45Q) running firmware version v02.21.031 or below [1]. An attacker with physical access can exploit this by accessing the UART interface and performing memory extraction to obtain sensitive information, including cryptographic private keys, Wi-Fi credentials, and configuration data stored in RAM.

Exploitation

An attacker must have physical access to the targeted device to connect to the UART interface. No authentication or user interaction is required beyond gaining physical proximity. The attacker can then perform memory extraction from the device's RAM, retrieving cryptographic private keys, Wi-Fi credentials, and configuration data [1].

Impact

Successful exploitation allows unauthorized access to encrypted communications and the connected wireless network of the targeted device. This can lead to device impersonation, data decryption, and Man-in-the-Middle (MITM) attacks [1]. The attacker gains sensitive information that compromises the confidentiality and integrity of network communications.

Mitigation

As of the publication date, no patch or workaround has been disclosed in the available references. Users are advised to apply firmware updates from the vendor as soon as they become available and to restrict physical access to the devices [1].

References
  1. Vulnerability

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.