{"id":"CVE-2026-81305","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-81305","summary":"CM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity or integrity. An attacker with physical access to the device could…","details":"CM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity or integrity. An attacker with physical access to the device could supply a malicious script and execute arbitrary code in the security context of the affected device.","published":"2026-09-18T16:17:10.103","modified":"2026-09-18T16:17:10.103","cvss":{"score":6.8,"severity":"MEDIUM","vector":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-258-08.json"},{"type":"WEB","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-08"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-18T16:17:10.103"}}