Description
CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthenticated attacker with network access to the affected device could retrieve live camera video.
Published: 2026-09-18
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated remote viewing of live camera video (confidentiality breach).
Action: Contact Vendor
AI Analysis

Impact

CareCam CM2507 IP cameras expose a network video streaming service that does not enforce authentication. An attacker with network access can connect to the device and retrieve live video, exposing sensitive visual information to the attacker. This vulnerability results in a direct confidentiality compromise and may allow an adversary to gain insight into protected facilities or personnel movements. Based on the description, it is inferred that an attacker could leverage the unrestricted stream to observe facility operations or track personnel movements.

Affected Systems

The affected product is the CareCam HMT.CM2507 firmware for CM2507 IP cameras. No specific firmware versions are listed, suggesting that all current releases of this device are vulnerable. Users should verify if their devices run the HMT.CM2507 firmware and assess whether they are exposed to a network that could be accessed by attackers.

Risk and Exploitability

The vulnerability has a CVSS score of 8.7, indicating high severity. The EPSS score is 0.00302 (less than 1%), indicating a very low probability of exploitation. The vulnerability is not listed in CISA's KEV catalog, but the risk remains significant because it provides unauthenticated access to live video streams. Attacks would be limited to devices with network connectivity and would require the attacker to discover the device's management interface via protocols such as HTTP or RTSP. Based on the description, the likely attack vector is a direct network connection to the camera's streaming service over HTTP or RTSP.

Generated by OpenCVE AI on September 19, 2026 at 17:35 UTC.

Remediation

Vendor Workaround

CareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information.


OpenCVE Recommended Actions

  • Contact CareCam to obtain an updated firmware release or a confirmed fix for the authentication issue.
  • If a firmware update is not yet available, isolate the camera from untrusted networks using firewall rules or VLAN segmentation to prevent unauthorized access.
  • Disable the unauthenticated network video streaming function if possible, or restrict streaming access to approved IP addresses only.
  • Reach out to CareCam for guidance, noting they have not responded to CISA's outreach.

Generated by OpenCVE AI on September 19, 2026 at 17:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Carecam
Carecam hmt.cm2507 Firmware
Vendors & Products Carecam
Carecam hmt.cm2507 Firmware

Fri, 18 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthenticated attacker with network access to the affected device could retrieve live camera video.
Title CareCam CM2507 Missing Authentication for Critical Function
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Carecam Hmt.cm2507 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-21T18:14:07.279Z

Reserved: 2026-09-10T15:00:49.640Z

Link: CVE-2026-88259

cve-icon Vulnrichment

Updated: 2026-09-21T18:14:01.836Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T16:17:14.207

Modified: 2026-09-21T19:17:14.830

Link: CVE-2026-88259

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:28:59Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function