CPATH-2026-0003 · Medical IoT

Contec CMS8000 — unsigned-firmware load / hard-coded beacon

Two or more co-dominant consequence paths connect the public security record to a provisional CRITICAL consequence band.

Candidate bandCRITICAL
Co-dominant pathsFirmware trust root + Device-control safety + Data privacy

These paths are co-dominant because each reaches the record's highest candidate band, CRITICAL; no array-order tie-break is applied.

Causal model

What has to happen for this consequence to hold?

3 candidate paths · explicit source, inference, and assumption boundaries.

Authority · Co-dominant path

Firmware trust root

Unsigned binaries copied into the executable directory run as trusted monitor code beneath normal application controls.

CRITICAL
  1. accessSource-backed

    Proximity or local access

    The monitor connects to a hard-coded routable NFS host, so exploitation depends on controlling or intercepting that network position.

    EvidenceCISA ICSMA-25-030-01

  2. boundaryModel inference

    Cross-domain authority chain

    The default NFS fetch bridges a network host into persistent code execution and then into clinical monitoring behavior.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Firmware or trust-root authority

    Unsigned binaries copied into the executable directory run as trusted monitor code beneath normal application controls.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Firmware trust root

    Unsigned binaries copied into the executable directory run as trusted monitor code beneath normal application controls.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Fleet action or replacement

    The absence of a signed update path means recovery must replace or verify firmware across affected devices rather than apply a simple configuration change.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 2
Proximity or local access

The monitor connects to a hard-coded routable NFS host, so exploitation depends on controlling or intercepting that network position.

Execution complexityEC 3
Reproducible exploit workflow

Serving a compatible replacement binary is reproducible, but requires understanding the NFS layout and expected executable format.

ExposureEX 2
Access position limits exposure

The technique is easier to perform than it is to position against a target, so access is the constraining factor.

Model inference
Consequence
Physical / safetyPH 4
Severe therapy or actuation consequence

Code loaded as monitor firmware can suppress alarms or falsify patient state, creating a credible wrong-care pathway without claiming observed injury.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

Firmware-level code can read sensitive patient and operational state handled by the monitor.

Model inference
AuthorityAT 4
Firmware or trust-root authority

Unsigned binaries copied into the executable directory run as trusted monitor code beneath normal application controls.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

The default NFS fetch bridges a network host into persistent code execution and then into clinical monitoring behavior.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

The same hard-coded host and unsigned load design is shared across affected CMS8000 units and rebrands.

Operational assumption
Execution scaleSX 3
Deployment-wide with setup

An attacker with the required network position can repeat the replacement across reachable monitors, but setup is deployment-dependent.

Operational assumption
Recovery burdenOR 4
Fleet action or replacement

The absence of a signed update path means recovery must replace or verify firmware across affected devices rather than apply a simple configuration change.

Operational assumption
Confidence and status
Evidence strengthEV 3
Reproduced or strongly report-backed

CISA ICSMA-25-030-01 supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

LivenessLS Active
Active condition at scoring time

The public record did not establish a complete mitigation at scoring time; field exploitation is stated only where a cited source supports it.

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. Unsigned binaries copied into the executable directory run as trusted monitor code beneath normal application controls.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:FIRMWARE_TRUST_ROOT/RE:2/EC:3/EX:2/PH:4/DP:3/AT:4/CH:4/SR:4/SX:3/OR:4/EV:3/LS:ACTIVERead the scoring method →

Safety · Co-dominant path

Device-control safety

Malicious monitor code can falsify displayed vitals or suppress alarms that clinicians use, supporting a serious safety consequence without proving field harm.

CRITICAL
  1. accessSource-backed

    Proximity or local access

    Control begins when a monitor reaches the hard-coded NFS address and accepts content from an attacker-controlled or intercepted endpoint.

    EvidenceCISA ICSMA-25-030-01

  2. boundaryModel inference

    Cross-domain authority chain

    Network content becomes executable monitor behavior and then influences a clinical perception-to-care boundary.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Severe therapy or actuation consequence

    Malicious monitor code can falsify displayed vitals or suppress alarms that clinicians use, supporting a serious safety consequence without proving field harm.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Device-control safety

    Malicious monitor code can falsify displayed vitals or suppress alarms that clinicians use, supporting a serious safety consequence without proving field harm.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Fleet action or replacement

    Restoring confidence requires verified firmware across the installed base because ordinary updates do not establish signed provenance.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 2
Proximity or local access

Control begins when a monitor reaches the hard-coded NFS address and accepts content from an attacker-controlled or intercepted endpoint.

Execution complexityEC 3
Reproducible exploit workflow

The attacker must prepare monitor-compatible code and gain the required network position, a standard but deliberate exploitation workflow.

ExposureEX 2
Access position limits exposure

The technique is easier to perform than it is to position against a target, so access is the constraining factor.

Model inference
Consequence
Physical / safetyPH 4
Severe therapy or actuation consequence

Malicious monitor code can falsify displayed vitals or suppress alarms that clinicians use, supporting a serious safety consequence without proving field harm.

Model inference
Data / perceptionDP 4
Safety-driving perception or intimate data

The manipulated patient-monitoring state is perception data that can directly shape clinical decisions.

Model inference
AuthorityAT 3
Administrative or command authority

Executed replacement code can control monitor software and alarm behavior, though this path distinguishes device command authority from the signing root itself.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

Network content becomes executable monitor behavior and then influences a clinical perception-to-care boundary.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

The same insecure loading behavior is present across the affected product family, making the technique portable.

Operational assumption
Execution scaleSX 3
Deployment-wide with setup

Multiple reachable monitors can be targeted after deployment-specific network positioning, rather than through a universal internet endpoint.

Operational assumption
Recovery burdenOR 4
Fleet action or replacement

Restoring confidence requires verified firmware across the installed base because ordinary updates do not establish signed provenance.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

CISA ICSMA-25-030-01 reports the condition, but this registry has not independently reproduced this path.

LivenessLS Active
Active condition at scoring time

The public record did not establish a complete mitigation at scoring time; field exploitation is stated only where a cited source supports it.

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. Malicious monitor code can falsify displayed vitals or suppress alarms that clinicians use, supporting a serious safety consequence without proving field harm.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:3/EX:2/PH:4/DP:4/AT:3/CH:4/SR:4/SX:3/OR:4/EV:2/LS:ACTIVERead the scoring method →

Privacy · Co-dominant path

Data privacy

The beacon contains patient health information rather than low-sensitivity diagnostics or generic device telemetry.

CRITICAL
  1. accessSource-backed

    Network-reachable without prior access

    The monitor sends plaintext patient information to a hard-coded routable address by default, exposing the flow wherever that route can be observed or controlled.

    EvidenceCISA ICSMA-25-030-01

  2. boundaryModel inference

    Reusable multi-stage bridge

    A default device configuration moves clinical data across the monitor and network boundary to an external host.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Sensitive device or personal data

    The beacon contains patient health information rather than low-sensitivity diagnostics or generic device telemetry.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Data privacy

    The beacon contains patient health information rather than low-sensitivity diagnostics or generic device telemetry.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Coordinated operational recovery

    Recovery requires changing the destination and validating network and device configuration across deployed monitors.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

The monitor sends plaintext patient information to a hard-coded routable address by default, exposing the flow wherever that route can be observed or controlled.

Execution complexityEC 4
Straightforward operation

Receiving or observing the default plaintext beacon is straightforward once the network path is available.

ExposureEX 4
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 0
No direct physical effect

The same channel carries clinical state used in care, but this privacy path does not assert that disclosure alone caused patient harm.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

The beacon contains patient health information rather than low-sensitivity diagnostics or generic device telemetry.

Model inference
AuthorityAT 2
Bounded function authority

Receiving the beacon grants bounded access to exported data, not administrative control of the monitor or its firmware trust root.

Model inference
Scale and recovery
ChainabilityCH 3
Reusable multi-stage bridge

A default device configuration moves clinical data across the monitor and network boundary to an external host.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

The destination and beacon behavior are shared across affected monitors, so the collection method can be reused.

Operational assumption
Execution scaleSX 4
Remote fleet-scale execution

Plaintext egress can be collected across reachable units without interacting with each patient interface separately.

Operational assumption
Recovery burdenOR 3
Coordinated operational recovery

Recovery requires changing the destination and validating network and device configuration across deployed monitors.

Operational assumption
Confidence and status
Evidence strengthEV 3
Reproduced or strongly report-backed

CISA ICSMA-25-030-01 supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

LivenessLS Active
Active condition at scoring time

The public record did not establish a complete mitigation at scoring time; field exploitation is stated only where a cited source supports it.

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. The beacon contains patient health information rather than low-sensitivity diagnostics or generic device telemetry.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DATA_PRIVACY/RE:4/EC:4/EX:4/PH:0/DP:3/AT:2/CH:3/SR:4/SX:4/OR:3/EV:3/LS:ACTIVERead the scoring method →

Triage implication

Verify the authority transition before acting on the band.

Validate the deployment-specific transition from digital control or perception to physical action before setting remediation urgency.

Evidence ledger

Public sources used by this record.

Every named source includes a public link. Path review remains separate from citation coverage.

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipPaths model is higher
Baseline confidencehigh
Scored2026-06-03
v4.0 · 7.7 HIGHCISA/ICS-CERT via NVD (CVE-2025-0626)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
v3.1 · 7.5 HIGHCISA/ICS-CERT via NVD (CVE-2025-0626)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
v4.0 · 8.2 HIGHCISA/ICS-CERT via NVD (CVE-2025-0683)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
v3.1 · 5.9 MEDIUMCISA/ICS-CERT via NVD (CVE-2025-0683)
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

TL;DR

The Paths model rates all three paths CRITICAL because the device blindly loads unsigned firmware from a hard-coded routable IP. That trust-root failure forks into three distinct terminal harms: firmware control, safety/perception, and PHI egress. The published 7.7 / 8.2 baseline is retained for source review; the Paths drivers are multi-path consequence and hard recovery.

What it is

The CMS8000 mounts NFS from a hard-coded, routable IP and copies binaries to /opt/bin with no signature check, forcing the network interface up. It also beacons plaintext patient data (PHI) to that hard-coded address by default. Claroty Team82 reproduced the unsigned-code load and PHI egress, and — importantly — concluded this is insecure design, not a covert “backdoor.” (CISA ICSMA-25-030-01; Claroty Team82.)

Published baseline — scope note

Two bends, neither in the digit. (1) Label/narrative: CISA classed it CWE-912 “hidden functionality” and advised ripping devices off networks; the careful technical read (Team82) is “documented, insecure CMS default.” Same bytes, very different response — supplied by country-of-origin, not code (requirement #7). (2) Collapse: a single 7.7/8.2 cannot represent that one trust-root failure yields three terminal consequences at once, nor that there is no signed-update path to recover (the vendor shipped non-fixes).

Consequence driver

The Paths model highlights #2 (chain/multi-path) — one trust-root failure forks into three terminal harms a single number collapses; #8 (recoverability) — there is no signed-update path, so this is hard to fix in place; and #7 (narrative-invariance) — the “backdoor” framing moved the response, not the bytes.

Sources

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0003 (“Contec CMS8000 — unsigned-firmware load / hard-coded beacon”), paths.cfse.ai/CPATH-2026-0003 (published 2026-06-03).