Physical Debug Interface Vulnerability in CM2507 IP Camera
CVE-2026-85478

2.4LOW

Key Information:

Vendor

Carecam

Vendor
CVE Published:
18 September 2026

What is CVE-2026-85478?

A vulnerability in the CM2507 IP camera allows a physical attacker to exploit an interactive bootloader via a debug interface without authentication. This flaw enables unauthorized individuals with physical access to interrupt the normal boot process, potentially leading to unauthorized inspection or modifications of boot configuration and firmware data, compromising the integrity and security of the device.

Affected Version(s)

HMT.CM2507 Firmware v251211.1507

References

CVSS V4

Score:
2.4
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ben Law reported this vulnerability to CISA.
.