CVE-2026-84398
CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-profile, and stream configuration information.
- Published Sep 18, 2026
- CVSS 8.7 high
- 0.4% chance of exploitation in the next 30 days (EPSS)