AllCyberNews

CVE-2026-84398

CareCam CM2507 Empty Password in Configuration File

CVSS 8.7 high · CareCam HMT.CM2507 Firmware · published 2026-09-18

CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-profile, and stream configuration information.

Coverage 1 source

  1. 2026-09-15 CISA Cybersecurity Advisories high CareCam CM2507

    Multiple vulnerabilities in CareCam CM2507 could allow attackers to access live video, execute code, and modify device operation.

Mentioned with

CVE-2026-81305 CVE-2026-81321 CVE-2026-84400 CVE-2026-85478 CVE-2026-85497 CVE-2026-88259

Also covered