high · CVSS v3 7.5 · CVSS v4 8.7 · EPSS 0.00241
CVE-2026-84398
CM2507 IP cameras contain an authentication bypass vulnerability due to an accepted empty password for privileged accounts via the ONVIF man
Overview
CM2507 IP cameras contain an authentication bypass vulnerability due to an accepted empty password for privileged accounts via the ONVIF management service. Network-adjacent adversaries can leverage this flaw to access restricted device functions and configuration data. This exposure threatens device integrity and surveillance confidentiality.
Description
CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-profile, and stream configuration information.
Impact
Confidentiality and integrity are impacted as unauthorized users can view media streams, user lists, and device configurations. Administrative availability may also be compromised if settings are maliciously altered. This directly affects organizations deploying these cameras within unsegmented or insecure network zones.
Remediation
Apply the latest vendor-supplied firmware update that enforces strong authentication for all privileged accounts. Restrict network access to the ONVIF management service using internal firewalls, VLAN segmentation, and strict access control lists. Disable ONVIF services if they are not operationally required for camera functionality.
Risk context
The vulnerability carries a CVSS v4 score of 8.7 and a CVSS v3 score of 7.5, reflecting a high severity risk. Although the current EPSS is low at 0.00241, the exposure of default credentials on network-facing management interfaces requires prompt mitigation.
Affected products
- CM2507 IP Camera
- CM2507 Firmware
Scores
- Severity
- high
- CVSS v2
- 7.8
- CVSS v3
- 7.5
- CVSS v4
- 8.7
- EPSS
- 0.00241