CVE-2026-84400

Summary

CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism that can activate a remote debugging service. An attacker on the same local network who satisfies certain device state conditions could make the service remotely accessible, increasing the risk of unauthorized administrative access.

Affected Software

VendorProductVersion RangeStatus
CareCamHMT.CM2507 Firmwarev251211.1507affected

Weaknesses

  • CWE-306: CWE-306

Workarounds

CareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information.

References