CyberzSOC

Publication detail
← Back to advisories & guidance

CISA Releases Fact Sheet Detailing Embedded Backdoor Function of Contec CMS8000 Firmware ↗ source

January 30, 2025 CISA Alert

Summary

Healthcare and Public Health (HPH) sector. Analysts discovered that an embedded backdoor function with a hard-coded IP address, CWE – 912: Hidden Functionality ( CVE-2025-0626 ), and functionality that enables patient data spillage, CWE – 359: Exposure of Private Personal Information to an Unauthorized Actor ( CVE-2025-0683 ), exists in all versions analyzed. Please note the Contec CMS8000 may be re-labeled and sold by resellers. For a list of known re-labeled devices, please refer to FDA’s safety communication, Cybersecurity Vulnerabilities with Certain Patient Monitors from Contec and Epsimed: FDA Safety Communication . Contec Medical Systems, the company which manufactures this monitor as well as other medical device and healthcare solutions, is headquartered in Qinhuangdao, China. The Contec CMS8000 is used in medical settings across the U.S. and European Union to provide continuous monitoring of a patient’s vital signs—tracking electrocardiogram, heart rate, blood oxygen saturation, non-invasive blood pressure, temperature, and respiration rate.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-0683 8.2 High Contec Health CMS8000 Patient Monitor In its default configuration, Contec Health CMS8000 Patient Monitor transmits plain-text patient data to a hard-coded public IP address when a patie…
CVE-2025-0626 7.7 High Contec Health CMS8000 Patient Monitor The "monitor" binary in the firmware of the affected product attempts to mount to a hard-coded, routable IP address, bypassing existing device networ…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.