rootpwn

low · CVSS v3 3.1 · CVSS v4 2.3 · EPSS 0.00141

CVE-2026-84400

CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism capable of activating a remote debugging service

Overview

CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism capable of activating a remote debugging service. Local network attackers meeting specific device conditions can make this service remotely accessible. This flaw matters because it increases the risk of unauthorized administrative access to affected devices.

Description

CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism that can activate a remote debugging service. An attacker on the same local network who satisfies certain device state conditions could make the service remotely accessible, increasing the risk of unauthorized administrative access.

Impact

Impacts Confidentiality, Integrity, and Availability. Local network attackers can potentially gain unauthorized administrative access if specific device state conditions are met, threatening overall device security and local network trust boundaries.

Remediation

Apply vendor-supplied firmware updates if available. Isolate IP cameras onto a dedicated VLAN or segmented network to restrict local network access. Disable unnecessary maintenance and debugging services via administrative controls.

Risk context

The vulnerability is rated as low severity with a CVSS v3 score of 3.1 and a very low EPSS score of 0.00141, indicating a limited likelihood of active exploitation in the wild.

Affected products

  • CareCam CM2507 IP camera

Scores

Severity
low
CVSS v2
1.8
CVSS v3
3.1
CVSS v4
2.3
EPSS
0.00141

IoT IP Camera Network Maintenance Access Control Local Network

← All CVEs