CVE-2026-84398

Summary

CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-profile, and stream configuration information.

Affected Software

VendorProductVersion RangeStatus
CareCamHMT.CM2507 Firmwarev251211.1507affected

Weaknesses

  • CWE-258: CWE-258

Workarounds

CareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information.

References