Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
CareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 19 Sep 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Carecam
Carecam hmt.cm2507 Firmware |
|
| Vendors & Products |
Carecam
Carecam hmt.cm2507 Firmware |
Fri, 18 Sep 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthenticated attacker with network access to the affected device could retrieve live camera video. | |
| Title | CareCam CM2507 Missing Authentication for Critical Function | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-09-18T16:05:06.400Z
Reserved: 2026-09-10T15:00:49.640Z
Link: CVE-2026-88259
No data.
Status : Deferred
Published: 2026-09-18T16:17:14.207
Modified: 2026-09-18T19:03:28.367
Link: CVE-2026-88259
No data.
OpenCVE Enrichment
Updated: 2026-09-19T22:28:59Z
-
CWE-306
Missing Authentication for Critical Function