CVE-2026-88259: Carecam hmt.cm2507 Firmware
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthenticated attacker with network access to the affected device could retrieve live camera video.
Affected products
- Carecam hmt.cm2507 Firmware: version v251211.1507 only
Published 2026-09-18. Last modified 2026-09-21.