---
id: CVE-2026-88259
title: >-
  CareCam CM2507 IP cameras do not require authentication for access to its
  network video streaming service
summary: >-
  CareCam CM2507 IP cameras do not require authentication for access to its
  network video streaming service. An unauthenticated attacker with network
  access to the affected device could retrieve live camera video.
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-306
vendor: CareCam
product: HMT.CM2507 Firmware
affected:
  - hmt.cm2507_firmware v251211.1507
published: '2026-09-18'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T19:17:14.830'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88259'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-258-08.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-08'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
  - cve.org
epss: 0.0052
epssPercentile: 0.41655
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-21T18:13:55.440036Z'
ingestedAt: '2026-09-18T16:45:41.399Z'
---

## Overview

CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthenticated attacker with network access to the affected device could retrieve live camera video.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
