CVE-2026-88259 PUBLISHED

CareCam CM2507 Missing Authentication for Critical Function

Assigner: icscert
Reserved: 10.09.2026 Published: 18.09.2026 Updated: 18.09.2026

CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthenticated attacker with network access to the affected device could retrieve live camera video.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor CareCam
Product HMT.CM2507 Firmware
Versions Default: affected
  • Version v251211.1507 is affected

Workarounds

CareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information.

Credits

  • Ben Law reported this vulnerability to CISA. finder

References

Problem Types

  • CWE-306 CWE