Impact
CareCam CM2507 IP cameras use a legacy password hash algorithm that does not apply sufficient computational effort, allowing an attacker who obtains the firmware image or password database to recover the root account credential. Because the hash is fixed across devices, the credential may be reusable on other units using the same firmware. This flaw enables offline credential compromise, potentially granting an attacker full control over affected cameras. The weakness is categorized as CWE‑916.
Affected Systems
Vendors: CareCam; Product: HMT.CM2507 Firmware; Affected devices are CareCam CM2507 IP cameras running the listed firmware. No specific version ranges are provided, so all firmware with the fixed legacy hash implementation is considered vulnerable.
Risk and Exploitability
The CVSS score of 9.3 marks this issue as critical, indicating substantial impact on confidentiality. With an EPSS score of 0.00206, the likelihood of exploitation is very low but non‑zero, reflecting that offline cracking remains feasible after acquiring the firmware or database. The likely attack vector involves offline cracking after the attacker has obtained the firmware image or password database, potentially through physical access or other firmware acquisition methods, and subsequently using the recovered credential on the device. The vulnerability is not listed in CISA KEV, but its high severity and the potential for credential reuse across devices amplify the risk for organizations that manage large fleets of CareCam cameras. Current mitigation is limited to contacting CareCam for a firmware update or other guidance, as no official patch or detailed workaround is available.
OpenCVE Enrichment