Impact
CareCam CM2507 IP cameras expose a network video streaming service that does not enforce authentication. An attacker with network access can connect to the device and retrieve live video, exposing sensitive visual information to the attacker. This vulnerability results in a direct confidentiality compromise and may allow an adversary to gain insight into protected facilities or personnel movements. Based on the description, it is inferred that an attacker could leverage the unrestricted stream to observe facility operations or track personnel movements.
Affected Systems
The affected product is the CareCam HMT.CM2507 firmware for CM2507 IP cameras. No specific firmware versions are listed, suggesting that all current releases of this device are vulnerable. Users should verify if their devices run the HMT.CM2507 firmware and assess whether they are exposed to a network that could be accessed by attackers.
Risk and Exploitability
The vulnerability has a CVSS score of 8.7, indicating high severity. The EPSS score is 0.00302 (less than 1%), indicating a very low probability of exploitation. The vulnerability is not listed in CISA's KEV catalog, but the risk remains significant because it provides unauthenticated access to live video streams. Attacks would be limited to devices with network connectivity and would require the attacker to discover the device's management interface via protocols such as HTTP or RTSP. Based on the description, the likely attack vector is a direct network connection to the camera's streaming service over HTTP or RTSP.
OpenCVE Enrichment