CVE-2026-84400

CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism that can activate a remote debugging service. An attacker on the same local network who satisfies certain device state conditions could make the service remotely accessible, increasing the risk of unauthorized administrative access.

  • Published Sep 18, 2026
  • CVSS 2.3 low
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-84400 at the National Vulnerability Database