{"id":"CVE-2026-85497","published":"2026-09-18T17:17:04.790","lastModified":"2026-09-21T19:17:13.757","description":"CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who obtains the firmware image or password database could recover the associated credential, which may also be reusable across other devices running the same firmware.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-916"],"vendors":[],"products":[],"references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-258-08.json","tags":[]},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-08","tags":[]}],"exploitRefs":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-258-08.json","tags":[]}],"hasPoc":true,"ai":{"summary":"The CareCam CM2507 IP cameras use a fixed legacy password hash for the root account, making it susceptible to offline cracking. This flaw allows an attacker to recover the password, posing a significant security risk.","exploitability":"Exploiting this flaw is relatively straightforward for an attacker who has obtained the firmware image or password database, as the fixed hash provides no resistance to offline cracking.","blast_radius":"If exploited, this flaw could lead to full device compromise, allowing an attacker to gain root access and potentially control the camera or other connected systems.","remediation":"Disable the affected feature or upgrade to the latest firmware version, specifically 'Upgrade to the latest firmware version available from the vendor'.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["password-cracking","firmware-update","root-access"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T09:02:02.601Z"}}