CM2507 网络摄像头在其通过 ONVIF 管理服务暴露的特权账户中,接受空密码。拥有对受影响设备的网络访问权限的攻击者可以访问特权管理功能,并获取设备、用户、媒体配置文件及流配置等信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| CareCam | HMT.CM2507 Firmware | v251211.1507 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| CareCam | HMT.CM2507 Firmware | v251211.1507 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85497 | 9.8 CRITICAL | CareCam CM2507 Use of Password Hash With Insufficient Computational Effort |
| CVE-2026-81321 | 9.8 CRITICAL | CareCam CM2507 Cleartext Storage of Sensitive Information |
| CVE-2026-88259 | 7.5 HIGH | CareCam CM2507 Missing Authentication for Critical Function |
| CVE-2026-81305 | 6.8 MEDIUM | CareCam CM2507 Inclusion of Functionality from Untrusted Control Sphere |
| CVE-2026-85478 | 3.5 LOW | CareCam CM2507 Missing Authentication for Critical Function |
| CVE-2026-84400 | 3.1 LOW | CareCam CM2507 Missing Authentication for Critical Function |
No comments yet