low · CVSS v3 3.1 · CVSS v4 2.3 · EPSS 0.00141
CVE-2026-84400
CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism capable of activating a remote debugging service
Overview
CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism capable of activating a remote debugging service. Local network attackers meeting specific device conditions can make this service remotely accessible. This flaw matters because it increases the risk of unauthorized administrative access to affected devices.
Description
CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism that can activate a remote debugging service. An attacker on the same local network who satisfies certain device state conditions could make the service remotely accessible, increasing the risk of unauthorized administrative access.
Impact
Impacts Confidentiality, Integrity, and Availability. Local network attackers can potentially gain unauthorized administrative access if specific device state conditions are met, threatening overall device security and local network trust boundaries.
Remediation
Apply vendor-supplied firmware updates if available. Isolate IP cameras onto a dedicated VLAN or segmented network to restrict local network access. Disable unnecessary maintenance and debugging services via administrative controls.
Risk context
The vulnerability is rated as low severity with a CVSS v3 score of 3.1 and a very low EPSS score of 0.00141, indicating a limited likelihood of active exploitation in the wild.
Affected products
- CareCam CM2507 IP camera
Scores
- Severity
- low
- CVSS v2
- 1.8
- CVSS v3
- 3.1
- CVSS v4
- 2.3
- EPSS
- 0.00141