CVE-2026-84398: CareCam CM2507 Empty Password in Configuration File
CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-profile, and stream configuration information.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
On CM2507, configure the ONVIF privileged account to require a non-empty password; do not allow an empty password in the device configuration file.
CareCam CM2507 (ONVIF privileged management service) Privileged account password = Set to a non-empty password (disable empty-password/empty-password acceptance)
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs network access to an affected CM2507 IP camera. No authentication or user interaction is required.
What access could an attacker gain?
An attacker could access privileged ONVIF management functions and obtain device, user, media-profile, and stream configuration information.
Is this limited to the camera's web interface?
The exposed privileged account is available through the camera's ONVIF management service. The provided information does not identify other affected management interfaces.