Executive brief
The CareCam CM2507 is an IP security camera used in commercial facilities worldwide. An attacker with physical access to the device can insert removable media containing a malicious script that the camera automatically executes without verifying authenticity, allowing arbitrary code execution on the device. This could enable attackers to compromise video feeds, modify device behavior, or use the compromised device as a foothold for further network intrusion.
Technical details
The CM2507 firmware automatically executes scripts from removable media without signature verification or integrity checks, a CWE-829 (untrusted control sphere) flaw. Exploitation requires physical access to insert malicious media, but once triggered, the attacker gains code execution in the device's security context. No patch is available as of the advisory date; CISA reports CareCam has not responded to coordination requests.
Affected products
- CareCam CM2507 HMT.CM2507 Firmware v251211.1507
Timeline
- 2026-09-15: disclosed
- 2026-09-18: advisory