From Health 201FailSystems

how automated healthcare fails, how you'd know, and what to do at each tier — every claim sourced, reviewed continuously


Incident

Contec CMS8000 patient monitors: hidden remote-access function disclosed by CISA and FDA

CISA and FDA reported that a low-cost patient monitor's firmware contained hidden functionality that could allow remote access and sent patient data to an external address; independent researchers later judged it an insecure design rather than an intentional backdoor.

Sources checked when written 26 September 2026

What happened

On 30 January 2025 CISA and FDA reported that Contec CMS8000 monitors (and relabeled Epsimed MN-120) contained hidden functionality connecting to hard-coded IP addresses, could be remotely controlled, and exfiltrated patient data once networked; the firmware could enable network interfaces even when disabled. CVEs included CVE-2025-0626 (hidden functionality) and CVE-2024-12248 (out-of-bounds write, CVSS v3.1 9.8). With no patch, FDA told users to unplug ethernet and disable wireless, or stop using the monitor if they depended on remote monitoring. A July 2025 patch removed networking entirely. FDA reported no known incidents, injuries or deaths. Two security firms analysed the firmware afterwards. Claroty's Team82 (2 February 2025) concluded the function was most likely not a hidden backdoor but an insecure design: the hard-coded address appears in the vendor's and resellers' manuals as the central management system, and an update needs a physical button press. Cylera (4 February 2025) called it not an intentional backdoor but an unfortunate use of a public IPv4 address range in an internal setting. CISA's updated advisory (25 February 2025) added a vulnerability credited to Claroty and still says the function could serve as a backdoor; FDA's communication still describes a backdoor.[1,2,3,4]

Documented harm

None documented (FDA, as of July 2025 update).

What it teaches

Sources

  1. Cybersecurity Vulnerabilities with Certain Patient Monitors from Contec and Epsimed: FDA Safety Communication. U.S. Food and Drug Administration, 30 January 2025. Primary Official report · link checked 2026-09-26
  2. ICS Medical Advisory ICSMA-25-030-01: Contec Health CMS8000 Patient Monitor (Update A). Cybersecurity and Infrastructure Security Agency, 30 January 2025. Primary Official report · link checked 2026-09-26
  3. Do the CONTEC CMS8000 Patient Monitors Contain a Chinese Backdoor? The Reality is More Complicated…. Claroty Team82, 2 February 2025. Supporting Vendor research · link checked 2026-09-27
  4. Contec Patient Vital Signs Monitor: Chinese Backdoor or Bad Design?. Cylera (Chad Waters, Apostolos Bakoyiannis), 4 February 2025. Supporting Vendor research · link checked 2026-09-27

All incidents · Devices · Connectivity & data

Information only, not advice. FailSystems is an aggregation and synthesis of published sources. It is not consulting, engineering, legal, regulatory or medical advice, and using it creates no professional relationship. Health systems are complex and no approach fits every organisation: anything you adopt is your own decision, at your own risk, and should be checked against the current official sources and by qualified people who know your setting. Full disclaimer.

Dealing with an incident right now? This site is a reference, not an incident-response service. Activate your organisation's emergency operations plan and incident command, and: