CVE-2026-79393
massHeap buffer overflow in Xiongmai XM530 IP camera Sofia daemon allows DoS, possible RCE
CVE-2026-79393 is a heap-based buffer overflow (CWE-122) in the WS-Addressing Action transformation function of the Sofia IPC daemon in Xiongmai XM530 IP camera firmware. A remote, unauthenticated attacker can trigger it by sending a crafted SOAP request in which the wsa5:Action string exceeds 128 bytes, overflowing a heap buffer in the network-facing daemon. At minimum this crashes the service, causing a denial of service; the advisory also notes that arbitrary code execution is potentially possible, although the published CVSS impact is availability-only (C:N/I:N/A:H) and no public proof-of-concept demonstrates RCE. Any camera built on the Xiongmai XM530 platform running firmware HMT.CM2005-v220608.1837 or earlier is affected, which includes many white-label camera brands that ship Xiongmai firmware. The issue is not on the CISA Known Exploited Vulnerabilities catalog, and no public exploit or confirmed in-the-wild exploitation is currently known.
What to do: Owners of XM530-based cameras (including white-label brands) should check their current firmware version via the device web interface or the vendor's tool and update to a fixed release newer than HMT.CM2005-v220608.1837 from Xiongmai or the camera brand's support site when available. Until patched, do not expose the camera's SOAP/ONVIF network service directly to the internet; place affected devices behind a VPN or firewall rules limiting access to trusted hosts, since no authentication is required to exploit this flaw.
| Xiongmai IP Camera XM530 firmware (Sofia IPC daemon) | HMT.CM2005-v220608.1837 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to cause a denial of service or potentially execute arbitrary code via a crafted SOAP request containing a wsa5:Action string exceeding 128 bytes.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.