how automated healthcare fails, how you'd know, and what to do at each tier — every claim sourced, reviewed continuously
CISA and FDA reported that a low-cost patient monitor's firmware contained hidden functionality that could allow remote access and sent patient data to an external address; independent researchers later judged it an insecure design rather than an intentional backdoor.
On 30 January 2025 CISA and FDA reported that Contec CMS8000 monitors (and relabeled Epsimed MN-120) contained hidden functionality connecting to hard-coded IP addresses, could be remotely controlled, and exfiltrated patient data once networked; the firmware could enable network interfaces even when disabled. CVEs included CVE-2025-0626 (hidden functionality) and CVE-2024-12248 (out-of-bounds write, CVSS v3.1 9.8). With no patch, FDA told users to unplug ethernet and disable wireless, or stop using the monitor if they depended on remote monitoring. A July 2025 patch removed networking entirely. FDA reported no known incidents, injuries or deaths. Two security firms analysed the firmware afterwards. Claroty's Team82 (2 February 2025) concluded the function was most likely not a hidden backdoor but an insecure design: the hard-coded address appears in the vendor's and resellers' manuals as the central management system, and an update needs a physical button press. Cylera (4 February 2025) called it not an intentional backdoor but an unfortunate use of a public IPv4 address range in an internal setting. CISA's updated advisory (25 February 2025) added a vulnerability credited to Claroty and still says the function could serve as a backdoor; FDA's communication still describes a backdoor.[1,2,3,4]
None documented (FDA, as of July 2025 update).
Information only, not advice. FailSystems is an aggregation and synthesis of published sources. It is not consulting, engineering, legal, regulatory or medical advice, and using it creates no professional relationship. Health systems are complex and no approach fits every organisation: anything you adopt is your own decision, at your own risk, and should be checked against the current official sources and by qualified people who know your setting. Full disclaimer.