The U.S. Cybersecurity and Infrastructure Security Administration (CISA) is warning that Contec CMS8000 devices , a widely used patient monitoring monitor, include a backdoor that silently sends patient data to a remote IP address and downloads and executes files on the device.
See also: Over 4,000 backdoors seized via expired domains

Contec is a leading China-based technology . It offers a wide range of medical devices, such as patient monitoring systems, diagnostic equipment and laboratory instruments, meeting the needs of the modern healthcare sector.
CISA was notified of the malicious activity by an external researcher, who disclosed the vulnerability in the service. While testing three Contec CMS8000 firmware packages, CISA researchers detected unusual network traffic to a hard-coded external IP address. This address had no connection to the company, but was associated with a university.
This led to the discovery of a backdoor in firmware that could download and execute files on the monitoring monitor without any indication. This vulnerability allowed remote command execution, as well as full access and control of the devices. At the same time, it was found that the device silently transmitted patient data to a coded address during its system startup.
None of these actions were logged, allowing the malicious activity to occur silently, without device administrators being notified.
See also: Cloud Atlas hackers use Microsoft Office vulnerability to distribute backdoors
While CISA did not name the university and removed the IP address, information says it is linked to a Chinese university. Additionally, the IP address is also encoded in software for other medical equipment, including a pregnancy monitor from another healthcare manufacturer in China.

While analyzing the firmware, CISA found that one of the monitoring device's executable files, 'monitor', contains a backdoor that issues a series of Linux commands that activate the device's network adapter (eth0) and then attempts to mount a remote NFS at the hardcoded IP address belonging to the university.
Currently, there is no code update available for devices that remove the backdoor and CISA recommends that all healthcare organizations disconnect these devices from the network if possible.
Additionally, the cybersecurity agency recommends that organizations check Contec CMS8000 monitoring monitors for any signs of a backdoor, such as displaying information other than the patient's physical condition.
See also: Chinese hackers Winnti target other hackers with Glutton backdoor
Backdoors are hidden ways to bypass authentication or other security mechanisms in a system, allowing unauthorized access. They can be intentionally placed by developers to detect bugs or maliciously introduced by attackers to exploit the system later. Backdoors pose significant security risks, as they undermine the integrity and confidentiality of the system, potentially exposing sensitive data or allowing further exploitation. Identifying and mitigating backdoors requires rigorous code review practices, robust testing, and maintaining up-to-date security protocols.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
