Impact
CareCam HMT.CM2507 IP cameras allow an empty password for a privileged account exposed through the ONVIF management service. An attacker who can reach the device over the network can authenticate as a privileged user with no credential, giving them access to privileged management functions and the ability to retrieve device, user, media-profile, and stream configuration information. This vulnerability results in unauthorized access to configuration data and could facilitate further attacks such as lateral movement or persistent compromise.
Affected Systems
Affected systems are CareCam HMT.CM2507 firmware devices. No specific version information is provided, so all installations of this firmware are potentially vulnerable until a corrective action is applied.
Risk and Exploitability
The vulnerability scores a CVSS of 8.7, indicating high severity. EPSS score of 0.00241 (<1%) indicates a very low exploitation probability, and the issue is not listed in CISA KEV. The likely attack vector is network access to the device; an attacker only needs to send ONVIF management requests while the password field remains empty. Because no authentication is required, the exploitation path is trivial, creating a high risk for any exposed devices.
OpenCVE Enrichment