---
id: CVE-2026-85497
title: >-
  CareCam CM2507 IP cameras store the device's root-account password using a
  fixed legacy password hash that provides insufficient resistance to offline
  cracking
summary: >-
  CareCam CM2507 IP cameras store the device's root-account password using a
  fixed legacy password hash that provides insufficient resistance to offline
  cracking. An attacker who obtains the firmware image or password database
  could recove…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-916
vendor: CareCam
product: HMT.CM2507 Firmware
affected:
  - hmt.cm2507_firmware v251211.1507
published: '2026-09-18'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T19:17:13.757'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85497'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-258-08.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-08'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-21T18:46:18.091034Z'
epss: 0.00206
epssPercentile: 0.10941
ingestedAt: '2026-09-18T16:45:41.410Z'
---

## Overview

CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who obtains the firmware image or password database could recover the associated credential, which may also be reusable across other devices running the same firmware.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
