CVE-2026-79395
Received Received - Intake

Authentication Bypass in Xiongmai IP Camera Firmware

Vulnerability report for CVE-2026-79395, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: MITRE

Description

An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass authentication and execute privileged ONVIF actions (including PTZ control, stream URL retrieval, and system reboot) via a crafted SOAP request supplying the admin username with any arbitrary password when the account's stored password is empty.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-12
AI Q&A
2026-09-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
xiongmai xm530 to HMT.CM2005-v220608.1837 (exc)
xiongmai sofia_ipc_daemon to HMT.CM2005-v220608.1837 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an authentication bypass vulnerability in Xiongmai IP cameras. It allows remote attackers to bypass authentication by sending a crafted SOAP request with the admin username and any password when the account's stored password is empty. This lets them execute privileged ONVIF actions like PTZ control, stream URL retrieval, and system reboot.

Detection Guidance

To detect this vulnerability, check if the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 or earlier responds to crafted SOAP requests with the admin username and any password when the stored password is empty. Use network scanning tools like nmap to identify vulnerable devices and test ONVIF endpoints for improper authentication handling.

Impact Analysis

An attacker could gain full control of the affected IP camera, including accessing live video feeds, adjusting camera angles, rebooting the device, or changing configurations. This requires only network access and knowledge of the default admin username.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive video data, potentially violating privacy regulations like GDPR or HIPAA. Organizations using these cameras may face compliance failures due to inadequate authentication controls.

Mitigation Strategies

Immediately update the firmware to the latest version if available. Disable ONVIF WS-Security authentication if not required. Restrict network access to the Sofia IPC daemon using firewalls. Change the default admin password to a strong, unique value. Monitor device logs for suspicious SOAP requests or unauthorized access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79395. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart