AllCyberNews

CVE-2026-88259

CareCam CM2507 Missing Authentication for Critical Function

CVSS 8.7 high · CareCam HMT.CM2507 Firmware · published 2026-09-18

CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthenticated attacker with network access to the affected device could retrieve live camera video.

Coverage 1 source

  1. 2026-09-15 CISA Cybersecurity Advisories high CareCam CM2507

    Multiple vulnerabilities in CareCam CM2507 could allow attackers to access live video, execute code, and modify device operation.

Mentioned with

CVE-2026-81305 CVE-2026-81321 CVE-2026-84398 CVE-2026-84400 CVE-2026-85478 CVE-2026-85497

Also covered