CVE-2026-85497 PUBLISHED

CareCam CM2507 Use of Password Hash With Insufficient Computational Effort

Assigner: icscert
Reserved: 10.09.2026 Published: 18.09.2026 Updated: 18.09.2026

CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who obtains the firmware image or password database could recover the associated credential, which may also be reusable across other devices running the same firmware.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor CareCam
Product HMT.CM2507 Firmware
Versions Default: affected
  • Version v251211.1507 is affected

Workarounds

CareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information.

Credits

  • Ben Law reported this vulnerability to CISA. finder

References

Problem Types

  • CWE-916 CWE