CM2507 IP 相机会自动执行可移动存储介质上预定义的脚本,且不会验证其真实性或完整性。拥有该设备物理访问权限的攻击者可以提供一个恶意脚本,从而在受影响设备的安全上下文中执行任意代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| CareCam | HMT.CM2507 Firmware | v251211.1507 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| CareCam | HMT.CM2507 Firmware | v251211.1507 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85497 | 9.8 CRITICAL | CareCam CM2507 Use of Password Hash With Insufficient Computational Effort |
| CVE-2026-81321 | 9.8 CRITICAL | CareCam CM2507 Cleartext Storage of Sensitive Information |
| CVE-2026-88259 | 7.5 HIGH | CareCam CM2507 Missing Authentication for Critical Function |
| CVE-2026-84398 | 7.5 HIGH | CareCam CM2507 Empty Password in Configuration File |
| CVE-2026-85478 | 3.5 LOW | CareCam CM2507 Missing Authentication for Critical Function |
| CVE-2026-84400 | 3.1 LOW | CareCam CM2507 Missing Authentication for Critical Function |
No comments yet