Agencies Sound Alarm on Patient Monitors With Hardcoded Backdoor
ID: 84dcd5c5-5668-5c28-851c-6c42230d6273
STIX ID: report--84dcd5c5-5668-5c28-851c-6c42230d6273
Feed Name: Dark Reading
Date Published: 2025-02-06
Date Updated: 2026-04-21
Author: Kristina Beek, Associate Editor, Dark Reading
CISA and the FDA issued alerts about Contec CMS8000 and Epsimed MN-120 patient monitors that appear to contain a backdoor allowing remote control, network pivoting, and potential exfiltration of patient data; Claroty Team82's firmware research contends this is more likely insecure design (hardcoded CMS IP and exposed upgrade flow) than deliberate malware and recommends blocking WAN firmware upgrades, network segmentation, and robust vulnerability detection and patching to protect patients and networks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
