CVE-2026-84398: CareCam CM2507 Empty Password in Configuration File

Published Sep 18, 2026
·
Updated

CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-profile, and stream configuration information.

Affected Software

1 affected component
CareCam CM2507

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    On CM2507, configure the ONVIF privileged account to require a non-empty password; do not allow an empty password in the device configuration file.

    CareCam CM2507 (ONVIF privileged management service) Privileged account password = Set to a non-empty password (disable empty-password/empty-password acceptance)

Event History

Sep 18, 2026
CVE Published
via MITRE·04:07 PM
Data Sourced
via MITRE·04:07 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs network access to an affected CM2507 IP camera. No authentication or user interaction is required.

2

What access could an attacker gain?

An attacker could access privileged ONVIF management functions and obtain device, user, media-profile, and stream configuration information.

3

Is this limited to the camera's web interface?

The exposed privileged account is available through the camera's ONVIF management service. The provided information does not identify other affected management interfaces.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203