Description
A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physical debug interface without requiring authentication. An attacker with physical access could interrupt the normal boot process and access functionality that permits inspection or modification of boot configuration, firmware data, and software loaded by the device.
Published: 2026-09-18
Score: 2.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized firmware modification
Action: Restrict Access
AI Analysis

Impact

A CareCam CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader via a physical debug interface that can be accessed without authentication. The bootloader permits an attacker who can physically reach the debug port to interrupt normal boot and inspect or alter boot configuration, firmware data, and the software loaded by the device. This weakness enables unauthorized modification of the device’s firmware, potentially allowing attackers to install malicious code or create a persistent backdoor.

Affected Systems

This vulnerability affects CareCam’s HMT.CM2507 firmware version HMT.CM2507 v251211.1507, specifically the CM2507 IP camera model produced by CareCam.

Risk and Exploitability

The CVSS score of 2.4 classifies the flaw as low severity, and the EPSS score is under 1%, indicating a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Exploitation requires physical access to the debug interface, so the risk depends on the strength of physical security controls protecting the device. If physical access is obtained, an attacker can reset the firmware or inject malicious payloads that persist across reboots.

Generated by OpenCVE AI on September 19, 2026 at 16:50 UTC.

Remediation

Vendor Workaround

CareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information.


OpenCVE Recommended Actions

  • Physically secure or disconnect the debug interface to prevent unauthorized access.
  • Contact CareCam or await an official firmware update that enforces authentication on the bootloader. If a patch is not yet available, consider disconnecting the debug port and using hardware tamper‑protection measures.
  • Monitor device logs and boot activity for unexpected bootloader usage, and audit firmware integrity regularly.

Generated by OpenCVE AI on September 19, 2026 at 16:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Carecam
Carecam hmt.cm2507 Firmware
Vendors & Products Carecam
Carecam hmt.cm2507 Firmware

Fri, 18 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physical debug interface without requiring authentication. An attacker with physical access could interrupt the normal boot process and access functionality that permits inspection or modification of boot configuration, firmware data, and software loaded by the device.
Title CareCam CM2507 Missing Authentication for Critical Function
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 2.4, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Carecam Hmt.cm2507 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-21T18:45:56.301Z

Reserved: 2026-09-10T15:00:49.629Z

Link: CVE-2026-85478

cve-icon Vulnrichment

Updated: 2026-09-21T18:45:51.657Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T17:17:04.633

Modified: 2026-09-21T19:17:13.610

Link: CVE-2026-85478

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:28:47Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function