CVE-2026-81305Medium· 6.8▾ SunlitCM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity or integrity. An attacker with physical access to the device could supply a malicious script and execute arbitrary cod…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
CM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity or integrity. An attacker with physical access to the device could supply a malicious script and execute arbitrary code in the security context of the affected device.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-85478Low· 3.5A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physical debug interface without requiring authentication
CVE-2026-85497Critical· 9.8CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking
CVE-2026-81321Critical· 9.8CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem
CVE-2026-88259High· 7.5CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service
CVE-2026-84398High· 7.5CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service
CVE-2026-84400Low· 3.1CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism that can activate a remote debugging service