CVE-2026-84400 PUBLISHED

CareCam CM2507 Missing Authentication for Critical Function

Assigner: icscert
Reserved: 10.09.2026 Published: 18.09.2026 Updated: 18.09.2026

CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism that can activate a remote debugging service. An attacker on the same local network who satisfies certain device state conditions could make the service remotely accessible, increasing the risk of unauthorized administrative access.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 2.3

Product Status

Vendor CareCam
Product HMT.CM2507 Firmware
Versions Default: affected
  • Version v251211.1507 is affected

Workarounds

CareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information.

Credits

  • Ben Law reported this vulnerability to CISA. finder

References

Problem Types

  • CWE-306 CWE