CVE-2026-79395
largeAuthentication Bypass in Xiongmai XM530 IP Camera ONVIF SOAP Interface
An improper authentication flaw (CWE-287) exists in the WS-Security (wsse:UsernameToken) verification routine of the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware, where a non-empty password check is not enforced against the supplied credential. An unauthenticated remote attacker can send a crafted SOAP request that presents the admin username with any arbitrary password, and authentication succeeds when the account's stored password is empty. Successful exploitation grants access to privileged ONVIF actions, including PTZ (pan-tilt-zoom) control, retrieval of stream URLs, and system reboot. Affected devices are Xiongmai XM530 cameras running firmware HMT.CM2005-v220608.1837 or earlier, particularly those with the ONVIF service enabled and an admin account left with a blank password. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and no in-the-wild exploitation has been confirmed.
What to do: Update XM530 cameras to firmware newer than HMT.CM2005-v220608.1837 when Xiongmai releases it. Immediately set a strong, non-empty admin password (the flaw only works against accounts with a stored empty password) and restrict or disable the ONVIF service so it is not reachable from the internet. Check devices for blank-password admin accounts and audit for unexpected PTZ commands, stream access, or reboots.
| Xiongmai IP Camera XM530 (Sofia IPC daemon, ONVIF/WS-Security) | HMT.CM2005-v220608.1837 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass authentication and execute privileged ONVIF actions (including PTZ control, stream URL retrieval, and system reboot) via a crafted SOAP request supplying the admin username with any arbitrary password when the account's stored password is empty.
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.