{"id":"CVE-2026-88259","title":"CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service","summary":"CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthenticated attacker with network access to the affected device could retrieve live camera video.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-306"],"vendor":"CareCam","product":"HMT.CM2507 Firmware","affected":["hmt.cm2507_firmware v251211.1507"],"published":"2026-09-18","updated":"2026-09-21","sourceUpdated":"2026-09-21T19:17:14.830","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-88259","references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-258-08.json","label":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-08","label":"ics-cert@hq.dhs.gov"}],"tags":["nvd","cve.org"],"epss":0.00302,"epssPercentile":0.23186,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-21T18:13:55.440036Z"},"ingestedAt":"2026-09-18T16:45:41.399Z","slug":"CVE-2026-88259","body":"## Overview\n\nCareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthenticated attacker with network access to the affected device could retrieve live camera video.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}