CVE-2026-85478 PUBLISHED

CareCam CM2507 Missing Authentication for Critical Function

Assigner: icscert
Reserved: 10.09.2026 Published: 18.09.2026 Updated: 18.09.2026

A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physical debug interface without requiring authentication. An attacker with physical access could interrupt the normal boot process and access functionality that permits inspection or modification of boot configuration, firmware data, and software loaded by the device.

Metrics

CVSS Vector: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 2.4

Product Status

Vendor CareCam
Product HMT.CM2507 Firmware
Versions Default: affected
  • Version v251211.1507 is affected

Workarounds

CareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information.

Credits

  • Ben Law reported this vulnerability to CISA. finder

References

Problem Types

  • CWE-306 CWE