CVE-2026-79396

Xiongmai · IP Camera XM530

Xiongmai IP Camera XM530 firmware contains hardcoded default credentials in plaintext, allowing unauthenticated remote attackers to gain full administrative control over the device.

Executive summary

A critical vulnerability in Xiongmai IP Camera XM530 firmware allows unauthenticated remote attackers to achieve full administrative access due to the presence of hardcoded credentials.

Vulnerability

The device uses hardcoded default credentials stored in plaintext within the configuration files and the Sofia executable. This flaw allows an unauthenticated attacker to bypass authentication mechanisms entirely.

Business impact

The exploitation of this vulnerability grants an attacker complete administrative control over the affected camera, potentially leading to unauthorized surveillance, data interception, or the integration of the device into a botnet. Given the CVSS score of 9.8, this represents a critical risk that could result in severe reputational damage and the compromise of physical security infrastructure.

Remediation

Immediate Action: As no specific patch version is currently identified, users should isolate affected cameras from the public internet immediately and change default credentials if the firmware interface permits.

Proactive Monitoring: Security teams should monitor network traffic for anomalous connection attempts to the camera management ports and audit system logs for unauthorized configuration changes.

Compensating Controls: Deploy the affected devices behind a restrictive firewall or VPN, ensuring they are not reachable from external networks to prevent remote exploitation.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the linked research write-up by ShiroiBoushi.

Analyst recommendation

This vulnerability presents a severe risk to organizational security by allowing full device takeover without authentication. Administrators must prioritize the isolation of these devices from external network access until a vendor-supplied firmware update is verified and applied. Immediate network segmentation is the most effective measure to mitigate this critical exposure.

More Xiongmai CVEs

History

CVE Brief tracked this CVE 4 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.8 (3.1)
  4. Analyst report written

Sources