---
id: CVE-2026-85478
title: >-
  A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an
  interactive bootloader through a physical debug interface without requiring
  authentication
summary: >-
  A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an
  interactive bootloader through a physical debug interface without requiring
  authentication. An attacker with physical access could interrupt the normal
  boot p…
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-306
vendor: CareCam
product: HMT.CM2507 Firmware
affected:
  - hmt.cm2507_firmware v251211.1507
published: '2026-09-18'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T19:17:13.610'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85478'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-258-08.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-08'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-21T18:45:46.467374Z'
epss: 0.00162
epssPercentile: 0.05879
ingestedAt: '2026-09-18T16:45:41.411Z'
---

## Overview

A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physical debug interface without requiring authentication. An attacker with physical access could interrupt the normal boot process and access functionality that permits inspection or modification of boot configuration, firmware data, and software loaded by the device.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
