CVE-2026-84398
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Summary
CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-profile, and stream configuration information.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| CareCam | HMT.CM2507 Firmware | v251211.1507 | affected |
Weaknesses
- CWE-258: CWE-258
Workarounds
CareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information.
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-08
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-258-08.json
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.