CareCam CM2507 IP摄像头未对其网络视频流服务实施身份验证。任何能够访问受影响设备的网络攻击者,在未进行身份认证的情况下即可获取实时的摄像头视频流。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| CareCam | HMT.CM2507 Firmware | v251211.1507 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| CareCam | HMT.CM2507 Firmware | v251211.1507 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85497 | 9.8 CRITICAL | CareCam CM2507 Use of Password Hash With Insufficient Computational Effort |
| CVE-2026-81321 | 9.8 CRITICAL | CareCam CM2507 Cleartext Storage of Sensitive Information |
| CVE-2026-84398 | 7.5 HIGH | CareCam CM2507 Empty Password in Configuration File |
| CVE-2026-81305 | 6.8 MEDIUM | CareCam CM2507 Inclusion of Functionality from Untrusted Control Sphere |
| CVE-2026-85478 | 3.5 LOW | CareCam CM2507 Missing Authentication for Critical Function |
| CVE-2026-84400 | 3.1 LOW | CareCam CM2507 Missing Authentication for Critical Function |
No comments yet