Junglewise Threat Intelligence

CVE-2026-85497: CareCam CM2507 weak password hash in root account

CVE-2026-85497 · Severity: critical · CVSS 9.8 · Published 2026-09-18

Technologies: CareCam CM2507. Vendors: CareCam.

Executive brief

CareCam CM2507 IP cameras used for video surveillance store the root-account password using a legacy hash algorithm with insufficient computational resistance to cracking. An attacker who gains access to firmware images or password databases can recover the root credential offline, potentially reusing it across multiple cameras running the same firmware to take full control and access live video feeds.

Technical details

The vulnerability involves use of a weak password hash algorithm (CWE-916: Use of Password Hash With Insufficient Computational Effort) in the root account storage mechanism. An attacker with access to firmware binaries or extracted password databases can perform offline dictionary or brute-force attacks to recover the plaintext credential. The recovered root password may be valid across other CM2507 devices running identical firmware, enabling widespread administrative compromise.

Affected products

  • CareCam CM2507 HMT.CM2507 v251211.1507

Timeline

  • 2026-09-15: disclosed
  • 2026-09-18: advisory

References

Related threats