CareCam HMT.CM2507

7 known vulnerabilities in CareCam HMT.CM2507, 2 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-85497 CVSS 9.3 critical CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient…
  • CVE-2026-85478 CVSS 2.4 low A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physical debug interface…
  • CVE-2026-81321 CVSS 9.3 critical CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An attacker who obtains…
  • CVE-2026-88259 CVSS 8.7 high CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthenticated attacker…
  • CVE-2026-84400 CVSS 2.3 low CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism that can activate a remote debugging service…
  • CVE-2026-84398 CVSS 8.7 high CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network…
  • CVE-2026-81305 CVSS 7.0 high CM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity or integrity. An…