CVE-2025-0626
HIGH EXPLOITEDContec CMS8000 Patient Monitor Firmware - Hardcoded IP Backdoor File Overwrite
Title source: manualExploitation Summary
CVE-2025-0626 has been observed exploited in the wild (reported by VulnCheck KEV).
Description
The "monitor" binary in the firmware of the affected product attempts to mount to a hard-coded, routable IP address, bypassing existing device network settings to do so. The function also enables the network interface of the device if it is disabled. The function is triggered by attempting to update the device from the user menu. This could serve as a backdoor to the device, and could lead to a malicious actor being able to upload and overwrite files on the device.
References (4)
Core 4
Core References
Various Sources
https://www.bleepingcomputer.com/news/security/backdoor-found-in-two-healthcare-patient-monitors-linked-to-ip-in-china/
Third Party Advisory, US Government Resource
https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-030-01
Third Party Advisory, US Government Resource
https://www.cisa.gov/resources-tools/resources/contec-cms8000-contains-backdoor
Scores
CVSS v3
7.5
EPSS
0.0108
EPSS Percentile
60.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
VulnCheck KEV
2026-01-20
CWE
CWE-912
Status
published
Products (1)
Contec Health/CMS8000 Patient Monitor
All versions
Published
Jan 30, 2025
Tracked Since
Feb 18, 2026