CVE-2026-85497: CareCam CM2507 Use of Password Hash With Insufficient Computational Effort

Published Sep 18, 2026
·
Updated

CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who obtains the firmware image or password database could recover the associated credential, which may also be reusable across other devices running the same firmware.

Affected Software

1 affected component
CareCam CM2507 IP camera

Event History

Sep 18, 2026
CVE Published
via MITRE·04:19 PM
Data Sourced
via MITRE·04:19 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What must an attacker obtain before they can attempt to exploit this weakness?

An attacker needs access to the firmware image or the device password database. The described risk is offline cracking of the stored root-account password hash.

2

Which credential is at risk, and could the impact extend beyond one camera?

The affected credential is the device root-account password. If the recovered credential is reused, it may also work on other devices running the same firmware.

3

Is this directly exploitable over the network without first accessing device data?

The provided information describes an offline attack requiring the firmware image or password database. It does not state that the hash can be retrieved remotely from the camera.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203