Impact
A feature of the CareCam HMT.CM2507 IP camera firmware automatically runs any script found on a removable media device without performing authentication or integrity checks. An attacker who can physically access the device can supply a malicious script, allowing execution of arbitrary code in the camera’s security context and effectively taking full control of the unit.
Affected Systems
The vulnerability affects CareCam HMT.CM2507 firmware. No specific version information is provided in the advisory.
Risk and Exploitability
The CVSS score of 7 indicates a high severity. EPSS score of 0.00196 indicates a very low probability of exploitation, and the vulnerability is not in CISA’s KEV catalog. Because the issue requires physical access, the likelihood of exploitation by an external threat is lower than a remote vector, but organizations with unsecured camera environments may still expose themselves to moderate-to-high risk. An attacker could compromise camera control, exfiltrate sensitive imagery, or disable security functions. The ability to run arbitrary code underscores the seriousness of this flaw.
OpenCVE Enrichment