CVE-2026-79394
Received
Received - Intake
Insecure Default Configuration in Xiongmai IP Camera XM530 Firmware
Vulnerability report for CVE-2026-79394, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-11
Last updated on: 2026-09-11
Assigner: MITRE
Description
Description
An insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier ships with authentication disabled, allowing remote unauthenticated attackers to access live H.264 video and G.711 audio feeds in cleartext over unencrypted RTP/UDP.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| xiongmai | happytime_rtsp_server | to HMT.CM2005-v220608.1837 (exc) |
| xiongmai | xm530_firmware | HMT.CM2005-v220608.1837 |
| xiongmai | sofia_ipc_daemon | to HMT.CM2005-v220608.1837 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |