AllCyberNews

CVE-2026-85497

CareCam CM2507 Use of Password Hash With Insufficient Computational Effort

CVSS 9.3 critical · CareCam HMT.CM2507 Firmware · published 2026-09-18

CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who obtains the firmware image or password database could recover the associated credential, which may also be reusable across other devices running the same firmware.

Coverage 1 source

  1. 2026-09-15 CISA Cybersecurity Advisories high CareCam CM2507

    Multiple vulnerabilities in CareCam CM2507 could allow attackers to access live video, execute code, and modify device operation.

Mentioned with

CVE-2026-81305 CVE-2026-81321 CVE-2026-84398 CVE-2026-84400 CVE-2026-85478 CVE-2026-88259

Also covered