Impact
CareCam CM2507 IP cameras have an insufficiently protected network maintenance mechanism that can activate a remote debugging service. If an attacker can satisfy certain device state conditions on the same local network, the service becomes remotely accessible. This flaw allows the attacker to gain unauthorized administrative access to the camera. The weakness is an improper authentication vulnerability, as the service lacks proper credential checks.
Affected Systems
The affected product is CareCam HMT.CM2507 firmware. Users running this firmware model on their IP cameras are potentially vulnerable. No specific version details are provided.
Risk and Exploitability
The CVSS score of 2.3 indicates low severity. Because the EPSS score is < 1%, the current exploitation probability is very low, although it is not possible to quantify it precisely. The vulnerability requires the attacker to be on the same local network and meet specific device state conditions. Since it is not listed in the CISA KEV catalog, there is no publicly known exploitation yet. The flaw relies on insufficient authentication, so the risk is mainly local and depends on the attacker’s proximity to the camera. Given its low CVSS and lack of known exploits, the immediate risk to widespread attacks is low, but devices should still be inspected for exposed debugging services and, if possible, disabled or protected.
OpenCVE Enrichment