Description
CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism that can activate a remote debugging service. An attacker on the same local network who satisfies certain device state conditions could make the service remotely accessible, increasing the risk of unauthorized administrative access.
Published: 2026-09-18
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized administrative access via remote debugging service
Action: Assess Impact
AI Analysis

Impact

CareCam CM2507 IP cameras have an insufficiently protected network maintenance mechanism that can activate a remote debugging service. If an attacker can satisfy certain device state conditions on the same local network, the service becomes remotely accessible. This flaw allows the attacker to gain unauthorized administrative access to the camera. The weakness is an improper authentication vulnerability, as the service lacks proper credential checks.

Affected Systems

The affected product is CareCam HMT.CM2507 firmware. Users running this firmware model on their IP cameras are potentially vulnerable. No specific version details are provided.

Risk and Exploitability

The CVSS score of 2.3 indicates low severity. Because the EPSS score is < 1%, the current exploitation probability is very low, although it is not possible to quantify it precisely. The vulnerability requires the attacker to be on the same local network and meet specific device state conditions. Since it is not listed in the CISA KEV catalog, there is no publicly known exploitation yet. The flaw relies on insufficient authentication, so the risk is mainly local and depends on the attacker’s proximity to the camera. Given its low CVSS and lack of known exploits, the immediate risk to widespread attacks is low, but devices should still be inspected for exposed debugging services and, if possible, disabled or protected.

Generated by OpenCVE AI on September 19, 2026 at 17:30 UTC.

Remediation

Vendor Workaround

CareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information.


OpenCVE Recommended Actions

  • Disable or lock down the remote debugging service to enforce authentication before use, ensuring the service is only accessible with strong credentials.
  • Implement network segmentation or firewall rules to restrict local network access to the camera, limiting the attacker’s ability to reach the unprotected service.
  • Contact CareCam to obtain firmware updates that address the CWE-306 authentication flaw and apply any released patches promptly.

Generated by OpenCVE AI on September 19, 2026 at 17:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Carecam
Carecam hmt.cm2507 Firmware
Vendors & Products Carecam
Carecam hmt.cm2507 Firmware

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism that can activate a remote debugging service. An attacker on the same local network who satisfies certain device state conditions could make the service remotely accessible, increasing the risk of unauthorized administrative access.
Title CareCam CM2507 Missing Authentication for Critical Function
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Carecam Hmt.cm2507 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-19T14:11:43.861Z

Reserved: 2026-09-10T15:00:49.635Z

Link: CVE-2026-84400

cve-icon Vulnrichment

Updated: 2026-09-19T14:11:02.385Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T16:17:12.210

Modified: 2026-09-19T15:17:05.983

Link: CVE-2026-84400

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:28:53Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function