CareCam CM2507 IP cameras store configured wireless credentials as cleartext in the device filesystem. The exposed data includes the configured network identifier and pre-shared key. An attacker must obtain filesystem access, which the record says may occur through physical access, a debugging interface, or another vulnerability. This is CWE-312, but the public evidence does not identify the file path, data format, filesystem permissions, or any additional protection mechanism. The scoring metadata describes a network-reachable path with no authentication requirement, but the technical description does not establish that network access alone provides filesystem access.