CVE-2026-84398: Carecam hmt.cm2507 Firmware

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-profile, and stream configuration information.

Affected products

  • Carecam hmt.cm2507 Firmware: version v251211.1507 only

Published 2026-09-18. Last modified 2026-09-19.