Junglewise Threat Intelligence

CVE-2026-84398: CareCam CM2507 empty password in ONVIF management service

CVE-2026-84398 · Severity: high · CVSS 7.5 · Published 2026-09-18

Technologies: CareCam CM2507. Vendors: CareCam.

Executive brief

CareCam CM2507 IP cameras used in commercial facilities worldwide have a privileged account with an empty password exposed through the ONVIF management interface. An attacker on the network can use this empty password to access administrative functions and extract sensitive configuration data including user credentials, media profiles, and video stream settings, compromising camera operations and data security.

Technical details

The vulnerability is an empty password (CWE-258) for a privileged account accessible via the ONVIF management service with no authentication required. An attacker with network access can authenticate using the empty password to gain privileged management access. The attack vector is network-based with no authentication or user interaction required; no patch is mentioned as available.

Affected products

  • CareCam CM2507 HMT.CM2507 Firmware v251211.1507

Timeline

  • 2026-09-15: disclosed
  • 2026-09-18: advisory

References

Related threats