CVE-2026-56414
Received Received - Intake
Certificate File Upload Vulnerability in H.View IP Cameras

Publication date: 2026-06-26

Last updated on: 2026-06-26

Assigner: ICS-CERT

Description
A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arbitrary file content to fixed, persistent filesystem locations without validating file type, structure, or size. This design omission enables the placement of unexpected or malformed data in locations intended for trusted certificate material, which could affect system integrity or behavior even after reboot.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-26
Last Modified
2026-06-26
Generated
2026-06-27
AI Q&A
2026-06-27
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in H.View IP cameras' certificate-related upload interfaces. Authenticated users can upload arbitrary file content to fixed, persistent filesystem locations without any validation of the file type, structure, or size.

Because the system does not check the uploaded files, unexpected or malformed data can be placed in locations meant for trusted certificate material. This can compromise the system's integrity or behavior, even after the device is rebooted.

Impact Analysis

The vulnerability allows attackers with authenticated access to store arbitrary files in critical locations, potentially leading to system integrity issues or unexpected behavior.

This could result in compromised device functionality, persistent malicious code, or other security impacts that remain effective even after rebooting the device.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56414. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart