CVE-2026-85497: CareCam CM2507 Use of Password Hash With Insufficient Computational Effort
CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who obtains the firmware image or password database could recover the associated credential, which may also be reusable across other devices running the same firmware.
Affected Software
Event History
Frequently Asked Questions
What must an attacker obtain before they can attempt to exploit this weakness?
An attacker needs access to the firmware image or the device password database. The described risk is offline cracking of the stored root-account password hash.
Which credential is at risk, and could the impact extend beyond one camera?
The affected credential is the device root-account password. If the recovered credential is reused, it may also work on other devices running the same firmware.
Is this directly exploitable over the network without first accessing device data?
The provided information describes an offline attack requiring the firmware image or password database. It does not state that the hash can be retrieved remotely from the camera.