CISA and FDA reported that a low-cost patient monitor's firmware contained hidden functionality that could allow remote access and sent patient data to an external address; independent researchers later judged it an insecure design rather than an intentional backdoor.
Sources checked when written 26 September 2026
What happened
On 30 January 2025 CISA and FDA reported that Contec CMS8000 monitors (and relabeled Epsimed MN-120) contained hidden functionality connecting to hard-coded IP addresses, could be remotely controlled, and exfiltrated patient data once networked; the firmware could enable network interfaces even when disabled. CVEs included CVE-2025-0626 (hidden functionality) and CVE-2024-12248 (out-of-bounds write, CVSS v3.1 9.8). With no patch, FDA told users to unplug ethernet and disable wireless, or stop using the monitor if they depended on remote monitoring. A July 2025 patch removed networking entirely. FDA reported no known incidents, injuries or deaths.
Two security firms analysed the firmware afterwards. Claroty's Team82 (2 February 2025) concluded the function was most likely not a hidden backdoor but an insecure design: the hard-coded address appears in the vendor's and resellers' manuals as the central management system, and an update needs a physical button press. Cylera (4 February 2025) called it not an intentional backdoor but an unfortunate use of a public IPv4 address range in an internal setting. CISA's updated advisory (25 February 2025) added a vulnerability credited to Claroty and still says the function could serve as a backdoor; FDA's communication still describes a backdoor.[1,2,3,4]
Documented harm
None documented (FDA, as of July 2025 update).
What it teaches
Firmware can do things the settings screen says it does not; verify network behavior with traffic capture, not configuration.
The only mitigation for a compromised device may be to remove its connectivity, so plan for local-only operation.
Procurement must require an SBOM and a vulnerability disclosure process for every networked monitor, however cheap.
Information only, not advice. FailSystems is an aggregation and synthesis of published sources. It is not consulting, engineering, legal, regulatory or medical advice, and using it creates no professional relationship. Health systems are complex and no approach fits every organisation: anything you adopt is your own decision, at your own risk, and should be checked against the current official sources and by qualified people who know your setting. Full disclaimer.
Dealing with an incident right now? This site is a reference, not an incident-response service. Activate your organisation's emergency operations plan and incident command, and:
Power loss, disaster or resource needs: go through your local or county emergency management. They escalate to the state, and the state requests FEMA support; hospitals do not call FEMA directly.
A medical device problem: report it to the manufacturer and to FDA MedWatch.
Outside the US: your national emergency number and national cyber agency (in the UK, NCSC).