Loading market data...
← Back to CVE feed

CVE-2026-84398

HIGH CVSS 7.5 View on NVD ↗

Description

CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-profile, and stream configuration information.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Published: Sep 18, 2026 16:17 UTC Modified: Sep 18, 2026 19:03 UTC