CVE-2026-79396
massHardcoded Plaintext Credentials in Xiongmai XM530 IP Camera Firmware
Xiongmai XM530 IP camera firmware HMT.CM2005-v220608.1837 and earlier ships with hardcoded, static account credentials stored unencrypted in plaintext both in bin/config.xml and compiled directly into the Sofia executable. Because these credentials cannot be changed or removed through the normal user interface, a remote attacker who knows or recovers them can authenticate over the network with no privileges or user interaction required, gaining full administrative control of the camera, including its video feed, settings, and any credentials stored on the device. All XM530-based cameras running this firmware version or earlier are affected, including devices rebranded and resold under many OEM names. Xiongmai devices with default credentials have a long history of mass exploitation by IoT botnets such as Mirai, so the practical risk is high even though this specific CVE is not in the CISA KEV catalog. No public proof of concept or confirmed in-the-wild exploitation of this exact CVE is known at this time.
What to do: Immediately verify the firmware version on any XM530-based camera (including white-label/OEM units) and contact the vendor or reseller for a firmware newer than HMT.CM2005-v220608.1837. Because the backdoor credentials are baked into the Sofia binary and config.xml, simply changing the web UI password is not sufficient — remove cameras from direct internet exposure, place them on an isolated VLAN with strict firewall rules, and disable UPnP and any telnet/default accounts. Monitor device logs and network traffic for unexplained administrative logins, and plan to replace end-of-life cameras that cannot receive a fixed firmware.
| Xiongmai XM530 IP Camera firmware | HMT.CM2005-v220608.1837 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores static account credentials in unencrypted plaintext within bin/config.xml and compiled into the Sofia executable, allowing remote attackers to gain full administrative control over the camera.
- Weakness
- CWE-798
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.