SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-79395

CRITICAL · CVSS 9.8 EPSS 0.41% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The vulnerability allows remote attackers to bypass authentication in the WS-Security verification routine of the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware, enabling unauthorized execution of privileged ONVIF actions, such as PTZ control and system reboot, through a specially crafted SOAP request. This critical flaw affects devices with empty stored admin passwords, making them particularly susceptible to exploitation. Organizations using this firmware should prioritize immediate remediation to protect against potential unauthorized access and control of their IP cameras.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-79395
Severity
CRITICAL
CVSS
9.8
EPSS
0.41%

Original NVD Description

An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass authentication and execute privileged ONVIF actions (including PTZ control, stream URL retrieval, and system reboot) via a crafted SOAP request supplying the admin username with any arbitrary password when the account's stored password is empty.