运行固件版本 HMT.CM2507 v251211.1507 的 CM2507 IP 摄像头通过物理调试接口暴露了交互式引导加载程序(bootloader),且无需身份验证。拥有物理访问权限的攻击者可以中断正常的启动过程,并访问能够检查或修改启动配置、固件数据以及设备所加载的软件的功能。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| CareCam | HMT.CM2507 Firmware | v251211.1507 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| CareCam | HMT.CM2507 Firmware | v251211.1507 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85497 | 9.8 CRITICAL | CareCam CM2507 Use of Password Hash With Insufficient Computational Effort |
| CVE-2026-81321 | 9.8 CRITICAL | CareCam CM2507 Cleartext Storage of Sensitive Information |
| CVE-2026-88259 | 7.5 HIGH | CareCam CM2507 Missing Authentication for Critical Function |
| CVE-2026-84398 | 7.5 HIGH | CareCam CM2507 Empty Password in Configuration File |
| CVE-2026-81305 | 6.8 MEDIUM | CareCam CM2507 Inclusion of Functionality from Untrusted Control Sphere |
| CVE-2026-84400 | 3.1 LOW | CareCam CM2507 Missing Authentication for Critical Function |
No comments yet