CVE-2025-0626 Details
Description
The "monitor" binary in the firmware of the affected product attempts to mount to a hard-coded, routable IP address, bypassing existing device network settings to do so. The function also enables the network interface of the device if it is disabled. The function is triggered by attempting to update the device from the user menu. This could serve as a backdoor to the device, and could lead to a malicious actor being able to upload and overwrite files on the device.
A backdoor vulnerability has been identified in the Contec Health CMS8000 patient monitor, as well as in the Epsimed MN-120 patient monitor, which is a rebranded version of the CMS8000. This vulnerability allows unauthorized remote access to the device, enabling the execution of files and overwriting of existing ones. The issue arises from a hidden function in the 'monitor' binary of the device's firmware, which bypasses normal network settings to connect to a hard-coded IP address associated with a Chinese university. This connection facilitates the exfiltration of patient data, including personal identifiers and health information, to the same external IP address.
The FDA has advised against installing Contec's software patch, as it requires specialized expertise and could disrupt the device's functionality. Instead, healthcare providers should disconnect affected monitors from the internet and use only local monitoring features. For facilities unable to remove the devices from their networks, CISA recommends blocking the IP addresses 202.114.4.119 and 202.114.4.120.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 30, 2025CISA-ADP
Assessed Jan 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-912 | Hidden Functionality | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Contec CMS8000 | smart3250-2.6.27-wlan2.1.7.cramfs CMS7.820.075.08/0.74(0.75) CMS7.820.120.01/0.93(0.95) |
CPE
Remediation
| |
| Epsimed MN-120 | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 1, 2025 | CVE Modified | [email protected] |
| Jan 31, 2025 | CVE Modified | [email protected] |
| Jan 31, 2025 | CVE Modified | CVE |
| Jan 30, 2025 | New CVE Received | [email protected] |
Volerion