logo

Critical ‘Backdoor’ Discovered in Widely Used Healthcare Patient Monitors 

ID: c3aaea7c-0603-5e14-b29e-5f4331b9b6d1

STIX ID: report--c3aaea7c-0603-5e14-b29e-5f4331b9b6d1

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2025-02-01

Date Updated: 2026-04-22

Author: George V. Hulme

...
...

On January 30, 2025 the FDA and CISA disclosed that Contec CMS8000 (and Epsimed MN-120) patient monitors contain a persistent backdoor in firmware that mounts an NFS share from a hard-coded IP, can copy remote files (potentially modifying device firmware), streams patient data over LPD to port 5151, and may allow remote code execution; no patch is available, no incidents have been reported, and stakeholders are advised to disable network connectivity and rely on local monitoring or replace affected devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.