CVE-2026-84398
CareCam CM2507 Empty Password in Configuration File
CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-profile, and stream configuration information.
Coverage 1 source
-
2026-09-15
CISA Cybersecurity Advisories
high
CareCam CM2507
Multiple vulnerabilities in CareCam CM2507 could allow attackers to access live video, execute code, and modify device operation.
Mentioned with
CVE-2026-81305 CVE-2026-81321 CVE-2026-84400 CVE-2026-85478 CVE-2026-85497 CVE-2026-88259
Also covered
- CVE-2026-86950 Apple iOS and iPadOS
- CVE-2023-6548 Cloud Software Group NetScaler ADC
- CVE-2023-25608 Fortinet FortiAP-W2
- CVE-2026-88772 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
- CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands