CareCam CM2507 IP 摄像头存在一个保护不充分的网络维护机制,该机制可被用于激活远程调试服务。处于同一局域网内、且满足特定设备状态条件的攻击者,可使该服务变得可从远程访问,从而增加了未经授权获得管理权限的风险。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| CareCam | HMT.CM2507 Firmware | v251211.1507 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| CareCam | HMT.CM2507 Firmware | v251211.1507 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85497 | 9.8 CRITICAL | CareCam CM2507 Use of Password Hash With Insufficient Computational Effort |
| CVE-2026-81321 | 9.8 CRITICAL | CareCam CM2507 Cleartext Storage of Sensitive Information |
| CVE-2026-88259 | 7.5 HIGH | CareCam CM2507 Missing Authentication for Critical Function |
| CVE-2026-84398 | 7.5 HIGH | CareCam CM2507 Empty Password in Configuration File |
| CVE-2026-81305 | 6.8 MEDIUM | CareCam CM2507 Inclusion of Functionality from Untrusted Control Sphere |
| CVE-2026-85478 | 3.5 LOW | CareCam CM2507 Missing Authentication for Critical Function |
No comments yet