Critical Security Flaw Found in Contec CMS8000 Patient Monitor Firmware
2025-01-31
CISA issued a security advisory revealing critical vulnerabilities in the firmware of the Contec CMS8000 patient monitor. Analysis shows all three firmware versions analyzed contain a backdoor with a hardcoded IP address (CVE-2025-0626) and functionality that could lead to patient data spillage (CVE-2025-0683). These vulnerabilities could allow remote code execution and device modification, jeopardizing patient safety. CISA urges users to update firmware and take additional security measures.