PT-2026-95502 · Carecam · Hmt.Cm2507 Firmware

CVE-2026-85478

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

3.5

Low

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physical debug interface without requiring authentication. An attacker with physical access could interrupt the normal boot process and access functionality that permits inspection or modification of boot configuration, firmware data, and software loaded by the device.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85478

Affected Products

Hmt.Cm2507 Firmware