CVE-2026-81305

Summary

CM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity or integrity. An attacker with physical access to the device could supply a malicious script and execute arbitrary code in the security context of the affected device.

Affected Software

VendorProductVersion RangeStatus
CareCamHMT.CM2507 Firmwarev251211.1507affected

Weaknesses

  • CWE-829: CWE-829

Workarounds

CareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information.

References