logo

Backdoor found in two healthcare patient monitors, linked to IP in China

ID: 4aea2c7c-7a6c-54da-a2ea-51df8799d097

STIX ID: report--4aea2c7c-7a6c-54da-a2ea-51df8799d097

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-01-30

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

**Executive summary:** CISA and the FDA report that Contec CMS8000 patient monitors contain firmware functionality that mounts a hard-coded remote NFS share, copies and overwrites binaries (enabling remote code execution), and transmits patient-identifiable data to an external IP; Claroty later suggested the behavior may be an insecure, physical-button-triggered update mechanism, but the design still poses serious security and data-exfiltration risks and no complete patch is available, so healthcare operators are advised to disconnect affected devices when possible.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.