CVE-2026-81305
CareCam CM2507 Inclusion of Functionality from Untrusted Control Sphere
CM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity or integrity. An attacker with physical access to the device could supply a malicious script and execute arbitrary code in the security context of the affected device.
Coverage 1 source
-
2026-09-15
CISA Cybersecurity Advisories
high
CareCam CM2507
Multiple vulnerabilities in CareCam CM2507 could allow attackers to access live video, execute code, and modify device operation.
Mentioned with
CVE-2026-81321 CVE-2026-84398 CVE-2026-84400 CVE-2026-85478 CVE-2026-85497 CVE-2026-88259
Also covered
- CVE-2026-86950 Apple iOS and iPadOS
- CVE-2023-6548 Cloud Software Group NetScaler ADC
- CVE-2023-25608 Fortinet FortiAP-W2
- CVE-2026-88772 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
- CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands