CVE-2025-1204 Details
Description
The "update" binary in the firmware of the affected product sends attempts to mount to a hard-coded, routable IP address, bypassing existing device network settings to do so. The function triggers if the 'C' button is pressed at a specific time during the boot process. If an attacker is able to control or impersonate this IP address, they could upload and overwrite files on the device.
A vulnerability has been identified in the Contec CMS8000 patient monitor and its white-label OEM variants, all versions. The issue lies in the 'update' binary of the device's firmware, which hardcodes a routable IP address, bypassing the device's network settings. This functionality is triggered by pressing the 'C' button during the boot process. If an attacker can control or impersonate the specified IP address, they could exploit this vulnerability to upload and overwrite files on the device, potentially leading to unauthorized modifications or execution of malicious code.
It is recommended to block all outgoing network traffic to the 202.114.4.0/24 subnet, which includes the hardcoded IP addresses used by the patient monitor. Organizations should also consider replacing these monitors with more secure alternatives, unless the vendor releases a firmware update to address the vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 25, 2025CISA-ADP
Assessed Feb 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://claroty.com/team82/research/are-contec-cms8000-patient-monitors-infected-with-a-chinese-backdoor-the-reality-is-more-complicated?ref=vault33.org | [email protected] | ExploitRemedyTechnical Analysis |
| https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-030-01 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-912 | Hidden Functionality | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Contec CMS8000 | smart3250-2.6.27-wlan2.1.7.cramfs CMS7.820.075.08/0.74(0.75) CMS7.820.120.01/0.93(0.95) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 25, 2025 | New CVE Received | [email protected] |
Volerion