CVE-2026-81640
—Hard-Coded Wi-Fi Password Lets Attackers Join Wi-Fi-Enabled Camera's Network
CVE-2026-81640 is a use of hard-coded credentials (CWE-798) in a Wi-Fi-enabled camera, assigned by CISA's ICS-CERT: an attacker within wireless range can derive the camera's Wi-Fi password and connect to its wireless network. Per the CVSS 4.0 vector, the attack requires only adjacent network access with no privileges, special conditions, or user interaction. Once connected, the attacker defeats the access-point password as a security control and may be able to view the live video stream and reach device services, status interfaces, and firmware-update functionality. Any deployment of the affected camera is exposed, though the vendor, model, and affected version ranges are not named in the available data. There is no evidence of exploitation in the wild, no known public proof-of-concept, and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog.
What to do: Identify the affected camera vendor and model through the CISA ICS-CERT advisory for CVE-2026-81640 and apply the vendor's firmware update as soon as it is available. Until patched, do not rely on the camera's Wi-Fi access-point password as a security boundary; place the camera on a segmented network segment or wired connection where possible. Monitor the camera's wireless network for unexpected clients and restrict reachability of its status and firmware-update interfaces.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An attacker could derive the camera's Wi-Fi password and connect to its wireless network. This weakens or eliminates the security value of the access-point password and may expose the live video stream, device services, status interfaces, and firmware-update functionality.
- Weakness
- CWE-798
- Vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.