rootpwn

high · CVSS v3 7.5 · CVSS v4 8.7 · EPSS 0.00241

CVE-2026-84398

CM2507 IP cameras contain an authentication bypass vulnerability due to an accepted empty password for privileged accounts via the ONVIF man

Overview

CM2507 IP cameras contain an authentication bypass vulnerability due to an accepted empty password for privileged accounts via the ONVIF management service. Network-adjacent adversaries can leverage this flaw to access restricted device functions and configuration data. This exposure threatens device integrity and surveillance confidentiality.

Description

CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-profile, and stream configuration information.

Impact

Confidentiality and integrity are impacted as unauthorized users can view media streams, user lists, and device configurations. Administrative availability may also be compromised if settings are maliciously altered. This directly affects organizations deploying these cameras within unsegmented or insecure network zones.

Remediation

Apply the latest vendor-supplied firmware update that enforces strong authentication for all privileged accounts. Restrict network access to the ONVIF management service using internal firewalls, VLAN segmentation, and strict access control lists. Disable ONVIF services if they are not operationally required for camera functionality.

Risk context

The vulnerability carries a CVSS v4 score of 8.7 and a CVSS v3 score of 7.5, reflecting a high severity risk. Although the current EPSS is low at 0.00241, the exposure of default credentials on network-facing management interfaces requires prompt mitigation.

Affected products

  • CM2507 IP Camera
  • CM2507 Firmware

Scores

Severity
high
CVSS v2
7.8
CVSS v3
7.5
CVSS v4
8.7
EPSS
0.00241

cve authentication-bypass ip-camera onvif iot-security high-severity

← All CVEs