logo

Agencies Sound Alarm on Patient Monitors With Hardcoded Backdoor

ID: 84dcd5c5-5668-5c28-851c-6c42230d6273

STIX ID: report--84dcd5c5-5668-5c28-851c-6c42230d6273

Feed Name: Dark Reading

Threat Score
55/100

Date Published: 2025-02-06

Date Updated: 2026-04-21

Author: Kristina Beek, Associate Editor, Dark Reading

...
...

CISA and the FDA issued alerts about Contec CMS8000 and Epsimed MN-120 patient monitors that appear to contain a backdoor allowing remote control, network pivoting, and potential exfiltration of patient data; Claroty Team82's firmware research contends this is more likely insecure design (hardcoded CMS IP and exposed upgrade flow) than deliberate malware and recommends blocking WAN firmware upgrades, network segmentation, and robust vulnerability detection and patching to protect patients and networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.