Contec Health CMS8000 Patient Monitor Backdoor Vulnerability

Vulnerability

A backdoor vulnerability has been identified in the Contec Health CMS8000 patient monitor, as well as in the Epsimed MN-120 patient monitor, which is a rebranded version of the CMS8000. This vulnerability allows unauthorized remote access to the device, enabling the execution of files and overwriting of existing ones. The issue arises from a hidden function in the 'monitor' binary of the device's firmware, which bypasses normal network settings to connect to a hard-coded IP address associated with a Chinese university. This connection facilitates the exfiltration of patient data, including personal identifiers and health information, to the same external IP address.

Impact

Exploitation of this vulnerability could lead to unauthorized remote control of the patient monitor, allowing for file execution and overwriting, with potential for remote code execution. The backdoor also enables the leakage of confidential patient data to the hard-coded IP address.

Reproduction

The vulnerability is triggered by accessing the device's update function from the user menu. This action activates the backdoor, which then connects to the hard-coded IP address, bypassing the device's network settings. Once the connection is established, the backdoor can be used to upload and overwrite files on the device.

Remediation

The FDA has advised against installing Contec's software patch, as it requires specialized expertise and could disrupt the device's functionality. Instead, healthcare providers should disconnect affected monitors from the internet and use only local monitoring features. For facilities unable to remove the devices from their networks, CISA recommends blocking the IP addresses 202.114.4.119 and 202.114.4.120.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.6
remediation
8.3
relevance
0.0
threat
1.6
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.