← Back to search

CVE-2026-85497

9.8 CRITICALpublic exploit available

Published 2026-09-18 · Updated 2026-09-21

AI risk analysis

Summary
The CareCam CM2507 IP cameras use a fixed legacy password hash for the root account, making it susceptible to offline cracking. This flaw allows an attacker to recover the password, posing a significant security risk.
Exploitability
Exploiting this flaw is relatively straightforward for an attacker who has obtained the firmware image or password database, as the fixed hash provides no resistance to offline cracking.
Blast radius
If exploited, this flaw could lead to full device compromise, allowing an attacker to gain root access and potentially control the camera or other connected systems.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the affected feature or upgrade to the latest firmware version, specifically 'Upgrade to the latest firmware version available from the vendor'.
password-crackingfirmware-updateroot-access

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who obtains the firmware image or password database could recover the associated credential, which may also be reusable across other devices running the same firmware.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-916

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.