Executive brief
CareCam CM2507 is an IP camera that streams video over a network. This vulnerability allows anyone with network access to view live camera video without providing any authentication credentials. An attacker on the same network or internet could passively watch all video from affected cameras without being detected.
Technical details
The CM2507 does not require authentication for its network video streaming service, allowing unauthenticated remote access over the network. This is a missing authentication vulnerability (CWE-306) that exposes video content to any network-adjacent or remote attacker. No user interaction or special privileges are required; an attacker simply needs network connectivity to the device to retrieve live video streams.
Affected products
- CareCam CM2507 HMT.CM2507 Firmware v251211.1507
Timeline
- 2026-09-15: disclosed
- 2026-09-18: advisory