CareCam CM2507 Has Seven Critical Vulns, No Vendor Response
Three of the seven CVEs are remotely exploitable over the network without authentication, and the vendor has gone silent on CISA's coordination attempts.
TL;DR
CISA published an advisory Wednesday for the CareCam CM2507 IP camera (firmware v251211.1507), flagging seven vulnerabilities that expose live video, privileged ONVIF management, and stored credentials to unauthenticated remote attackers. CareCam has not responded to coordination attempts. There is no patch and no vendor-provided mitigation. CISA's recommended practice (network isolation) is the only remediation on the table. The alert lands one week after a separate CISA advisory for CareCam Pro cameras, which also named an unresponsive vendor.
The CM2507 advisory is the second CareCam alert CISA has published in a week. Last Tuesday it was the CareCam Pro IP camera with a hardcoded bootloader credential (ICSA-26-251-01). Now it's the CM2507 with seven distinct CVEs, three of them remotely exploitable without authentication.
CVE-2026-88259 is the most direct gut-punch: the camera's video streaming service requires no authentication. Anyone with network access to the device pulls live video. CVE-2026-84398 lets an attacker walk through a privileged ONVIF management account with an empty password, configuration data, user profiles, media profiles, stream configs, all open. And CVE-2026-85497 stores the root-account password under a fixed legacy hash. Crack it once offline and you've got the root credential for every CM2507 running the same firmware, which right now means every CM2507.
The remaining four CVEs require physical or local-network access: a maintenance backdoor that can open remote debugging (CVE-2026-84400), auto-execution of scripts from removable media (CVE-2026-81305), an unprotected bootloader debug interface (CVE-2026-85478), and cleartext Wi-Fi credentials on the filesystem (CVE-2026-81321). The physical-access vectors matter less for most deployments than the three network-facing ones, but they complete an ugly picture, there isn't a layer of this device's security model that holds.
No patch, no vendor, no timeline
CISA's advisory repeats the same sentence for all seven CVEs: "CareCam has not responded to CISA's attempts to coordinate." The recommended practice section is boilerplate, airgap or firewall these devices, don't expose them to the internet, use VPNs if remote access is unavoidable. This isn't a fix. It's a damage-limitation posture for devices already deployed in commercial facilities and, per CISA's sector tagging, potentially in government and municipal settings as well.
The advisory doesn't say whether CareCam has shipped patched firmware since the alert or whether CISA expects a response. For organizations with CM2507s in the field, Monday morning means inventorying every device, segmenting them from business networks, and verifying nothing is internet-facing. That's the remediation plan until CareCam surfaces.
Published ·Deep Fathom