VORANT. Threat Intelligence Sign in Get the full feed

CISA warns of CareCam CM2507 camera flaws

routine vulnerability manufacturing

Seven vulnerabilities in CareCam CM2507 IP cameras allow unauthenticated video access, credential recovery, and code execution; vendor unresponsive to CISA.

CISA published an ICS advisory detailing seven vulnerabilities affecting CareCam CM2507 IP cameras running firmware HMT.CM2507 v251211.1507. The most severe issues include missing authentication on the network video streaming service (CVE-2026-88259), allowing any network-adjacent attacker to view live video without credentials, and an ONVIF management service that accepts empty passwords (CVE-2026-84398), exposing device, user, and stream configuration data. Additional flaws include an insufficiently protected debug/maintenance mechanism that can be made remotely accessible (CVE-2026-84400), an unauthenticated interactive bootloader reachable via physical debug interface (CVE-2026-85478), and automatic execution of unsigned scripts from removable media (CVE-2026-81305), enabling arbitrary code execution given physical access.

Two further weaknesses compound the risk: root-account passwords are stored using a legacy hash with weak resistance to offline cracking (CVE-2026-85497), and Wi-Fi credentials are stored in cleartext on the filesystem (CVE-2026-81321), potentially enabling lateral compromise of the local wireless network if a device is physically accessed or its firmware extracted. CareCam, headquartered in China, has not responded to CISA's coordination attempts, so no vendor patch or mitigation is currently available. The devices are deployed worldwide in the Commercial Facilities sector.

No public exploitation has been reported to CISA at this time. Because there is no vendor fix, defenders operating these cameras should treat them as untrusted network devices: isolate them from business networks and the internet, deny direct remote/VPN exposure, restrict physical access to prevent debug-interface and removable-media attacks, and monitor for unusual ONVIF, video-streaming, or debug-service connections. Given the range of impacts—from anonymous live-video access to full device compromise and credential recovery—organizations should prioritize network segmentation as the primary compensating control.

Mentioned in this report

Vulnerabilities CVE-2026-81305CVE-2026-81321CVE-2026-84398CVE-2026-84400CVE-2026-85478CVE-2026-85497CVE-2026-88259

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-08

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free