VYPR
advisoryPublished Sep 15, 2026· 1 source

Multiple Vulnerabilities Found in CareCam CM2507 IP Cameras; Vendor Unresponsive

CISA has disclosed several critical vulnerabilities in CareCam CM2507 IP cameras, including missing authentication and weak password handling, potentially allowing unauthorized access and code execution.

CISA has issued a stark warning regarding multiple security vulnerabilities discovered in CareCam CM2507 IP cameras, specifically affecting the HMT.CM2507 Firmware v251211.1507. These flaws, detailed in an ICS-CERT advisory, could permit attackers to gain unauthorized access to live video feeds, sensitive device information, and potentially execute arbitrary code on the affected devices. The advisory highlights a significant lack of vendor response, as CareCam has not engaged with CISA's coordination efforts.

The vulnerabilities span several critical areas. CVE-2026-88259 points to a missing authentication mechanism for the network video streaming service, allowing unauthenticated attackers with network access to view live camera feeds. Another critical flaw, CVE-2026-84398, involves the acceptance of an empty password for a privileged account within the ONVIF management service. This enables attackers to access management functions and extract device configuration details.

Further complicating the security posture, CVE-2026-84400 describes an insufficiently protected network maintenance mechanism that can enable a remote debugging service. While requiring specific device state conditions and local network access, this could lead to unauthorized administrative control. Additionally, CVE-2026-81305, categorized under CWE-829, allows for the execution of arbitrary code if an attacker with physical access can supply a malicious script to the device via removable media, as the camera automatically executes scripts without verifying their authenticity.

Physical access also presents risks through CVE-2026-85478, which exposes an unauthenticated interactive bootloader via a physical debug interface. This allows an attacker with physical access to inspect or modify boot configurations and firmware. The security of stored credentials is also compromised by CVE-2026-85497, where the device's root password is stored using a legacy, weak password hash, making it susceptible to offline cracking if the firmware image or password database is obtained.

These vulnerabilities carry significant implications, particularly for sectors relying on surveillance and monitoring, such as commercial facilities. The potential for unauthorized video access and code execution poses risks to operational security and data privacy. The CVSS scores indicate a high severity for several of these flaws, with base scores reaching 7.5 (HIGH) for missing authentication and empty password vulnerabilities, and even higher in the CVSS v4.0 scoring.

The lack of response from CareCam is a critical concern. Without vendor-provided patches or mitigation guidance, users are left in a precarious position. CISA advises users to reach out to CareCam directly for any available information or support, but the absence of a vendor response suggests a prolonged period without official remediation.

This situation underscores the persistent risks associated with IoT and ICS devices, especially when manufacturers fail to prioritize security and engage with vulnerability disclosure processes. The wide deployment of such devices globally means that unpatched vulnerabilities can create widespread attack surfaces for malicious actors.

Organizations using CareCam CM2507 devices are urged to implement network segmentation, restrict access to the affected devices, and monitor network traffic for suspicious activity. Until CareCam provides a firmware update, users must rely on these compensating controls to mitigate the risks posed by these critical security weaknesses.

Synthesized by Vypr AI