Insufficient Password Hashing in CareCam IP Cameras
CVE-2026-85497
9.3CRITICAL
What is CVE-2026-85497?
The CareCam CM2507 IP cameras are affected by a vulnerability that involves storing the device's root-account password using a legacy hash method. This method offers inadequate protection against offline attacks, allowing potential attackers to recover the root password if they obtain either the firmware image or the password database. Additionally, credentials obtained through this vulnerability may be reused across other devices that operate on the same firmware, amplifying the risk of unauthorized access.
Affected Version(s)
HMT.CM2507 Firmware v251211.1507
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ben Law reported this vulnerability to CISA.
