ZeroHour

CVE-2026-79394

mass

Unauthenticated RTSP Video Access in Xiongmai XM530 IP Camera Firmware

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

The embedded Happytime RTSP server inside the Sofia IPC daemon of Xiongmai IP Camera XM530 firmware (HMT.CM2005-v220608.1837 and earlier) ships with authentication disabled, an insecure default configuration (CWE-1188). A remote attacker who can reach the camera's RTSP service over the network needs no credentials or user interaction to connect and stream live H.264 video and G.711 audio, which are additionally transmitted in cleartext over unencrypted RTP/UDP. The impact is confidentiality-only (CVSS 3.1: 7.5, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), so an attacker gains real-time surveillance feeds but cannot alter or disrupt the device. This firmware is embedded in Xiongmai XM530-based cameras, which are widely rebranded and sold under many white-label OEM brands, making affected devices hard to identify by brand name. No public proof of concept is known, the flaw is not on the CISA KEV list, and there is no evidence of in-the-wild exploitation to date, though the weakness is trivially discoverable by network scanning.

What to do: Remove any direct internet exposure of affected cameras (block inbound RTSP on TCP 554 and RTP/UDP streams at the firewall) and place them on an isolated network segment. Upgrade to firmware newer than HMT.CM2005-v220608.1837 if the vendor provides a fixed build that enables RTSP authentication, and verify by attempting an unauthenticated RTSP connection. Because streams are sent in cleartext with auth off by default, treat any unpatchable XM530-based white-label camera as publicly viewable and plan for replacement.

Affected
Xiongmai IP Camera XM530 firmware (embedded Happytime RTSP server within the Sofia IPC daemon)HMT.CM2005-v220608.1837 and earlier
Estimated exposure
massPlausibly >100,000 internet-exposed systems, with Xiongmai-based cameras deployed in the millions globally (order-of-magnitude estimate) — Internet-wide scan services (e.g., Shodan/Censys) have historically shown hundreds of thousands of Xiongmai-derived cameras and DVRs reachable online, and XM530 firmware ships across many white-label OEM brands, though the exact count…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier ships with authentication disabled, allowing remote unauthenticated attackers to access live H.264 video and G.711 audio feeds in cleartext over unencrypted RTP/UDP.

Weakness
CWE-1188
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.