CERT-In Vulnerability Note
CIVN-2026-0266
Information Exposure Vulnerability in CP-Plus Wi-Fi Camera
Original Issue Date:May 25, 2026
Severity Rating: MEDIUM
Systems Affected
- CP Plus Wi-Fi Camera CP-E38Q, CP-E48Q, CP-E25Q, CP-E35Q, CP-E45Q, CP-E28Q, CP-E21Q, CP-E31Q, CP-E41Q, CP-E24Q, CP-Z43Q, CP-E34Q, CP-E44Q, CP-T31Q, CP-V48Q, CP-V41Q, CP-Z45Q : Firmware version v02.21.031 or below
Overview
A vulnerability has been reported in CP-Plus Wi-Fi Camera, which could allow an attacker to gain unauthorized access to encrypted communications and connected wireless network of the targeted device.
Target Audience: End-users/ Administrators of CP Plus Wi-Fi Camera
Risk Assessment: Risk of exposure of cryptographic private keys, Wi-Fi credentials and configuration data Impact Assessment: Device impersonation, data decryption and Man-in-the-Middle (MITM) attacks.
Description
CP Plus Wi-Fi Camera is a wireless IP surveillance device used for remote video monitoring and network-based access.
This vulnerability exists in CP Plus Wi-Fi Camera due to improper protection of sensitive information in runtime memory. An attacker with physical access could exploit this vulnerability by accessing the UART interface and performing memory extraction to obtain sensitive information, including cryptographic private keys, Wi-Fi credentials and configuration data stored in RAM of the targeted device.
Successful exploitation of this vulnerability could allow unauthorized access to encrypted communications and connected wireless network of the targeted device.
Credit
This vulnerability is reported by Mohsin Quresh.
Solution
Upgrade CP Plus Wi-Fi Camera to the latest firmware version v02.21.041 through OTA using the Ezykam+ mobile application.
https://cpplusworld.com/products/ezyhome/ezykam
Vendor Information
CP Plus
https://cpplusworld.com/products/ezyhome/ezykam
References
CP Plus
https://cpplusworld.com/products/ezyhome/ezykam
CVE Name
CVE-2026-9274
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|