CVE-2026-5386
Deferred
Deferred - Pending Action
Unauthenticated Password Reset in KMW CCTV Security Cameras
Publication date: 2026-05-29
Last updated on: 2026-06-16
Assigner: ICS-CERT
Description
Description
The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password to a known value without authentication, granting full access to the camera feeds and settings.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| kmw | cctv_security_cameras | * |
| kmw | km_ip521 | * |
| kmw | km_ip421 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-620 | When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication. |