CVE-2026-84400

low

Description

CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism that can activate a remote debugging service. An attacker on the same local network who satisfies certain device state conditions could make the service remotely accessible, increasing the risk of unauthorized administrative access.

References

https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-08

https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-258-08.json

Details

Source: Mitre, NVD

Published: 2026-09-18

Updated: 2026-09-19

Risk Information

CVSS v2

Base Score: 1.8

Vector: CVSS2#AV:A/AC:H/Au:N/C:N/I:P/A:N

Severity: Low

CVSS v3

Base Score: 3.1

Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Severity: Low

CVSS v4

Base Score: 2.3

Vector: CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Severity: Low

EPSS

EPSS: 0.00141