CVE-2026-88259

Summary

CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthenticated attacker with network access to the affected device could retrieve live camera video.

Affected Software

VendorProductVersion RangeStatus
CareCamHMT.CM2507 Firmwarev251211.1507affected

Weaknesses

  • CWE-306: CWE-306

Workarounds

CareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information.

References