ZeroHour

CVE-2026-79395

large

Authentication Bypass in Xiongmai XM530 IP Camera ONVIF SOAP Interface

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

An improper authentication flaw (CWE-287) exists in the WS-Security (wsse:UsernameToken) verification routine of the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware, where a non-empty password check is not enforced against the supplied credential. An unauthenticated remote attacker can send a crafted SOAP request that presents the admin username with any arbitrary password, and authentication succeeds when the account's stored password is empty. Successful exploitation grants access to privileged ONVIF actions, including PTZ (pan-tilt-zoom) control, retrieval of stream URLs, and system reboot. Affected devices are Xiongmai XM530 cameras running firmware HMT.CM2005-v220608.1837 or earlier, particularly those with the ONVIF service enabled and an admin account left with a blank password. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and no in-the-wild exploitation has been confirmed.

What to do: Update XM530 cameras to firmware newer than HMT.CM2005-v220608.1837 when Xiongmai releases it. Immediately set a strong, non-empty admin password (the flaw only works against accounts with a stored empty password) and restrict or disable the ONVIF service so it is not reachable from the internet. Check devices for blank-password admin accounts and audit for unexpected PTZ commands, stream access, or reboots.

Affected
Xiongmai IP Camera XM530 (Sofia IPC daemon, ONVIF/WS-Security)HMT.CM2005-v220608.1837 and earlier
Estimated exposure
large≈100,000+ internet-exposed Xiongmai/HiSilicon-based cameras plausibly in scope; the subset with an empty admin password and ONVIF reachable is unknown — Public Shodan/Censys-class scans have long shown on the order of hundreds of thousands of Xiongmai-based cameras and DVRs exposed online, and Xiongmai devices commonly ship with ONVIF enabled and blank default admin passwords, but the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass authentication and execute privileged ONVIF actions (including PTZ control, stream URL retrieval, and system reboot) via a crafted SOAP request supplying the admin username with any arbitrary password when the account's stored password is empty.

Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.