No analysis available yet.
Vendor Solution
KMW has issued a firmware update to address this vulnerability. The firmware update can be found at: https://main.kmw.ro/pub/Firmware/521_421.zip KM-IP421 - will lose the cloud authorization after this update so users will need to contact customer support to re-authorize the P2P connection. If there are any issues customers are encouraged to contact KMW directly.
Vendor Workaround
KMW recommends connecting surveillance equipment on a separate network, allow only specific devices access to the internet, check for firmware updates regularly, and use cloud connections responsibly.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 29 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password to a known value without authentication, granting full access to the camera feeds and settings. | |
| Title | KMW CCTV Security Cameras Unverified Password Change | |
| Weaknesses | CWE-620 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-05-29T16:25:17.079Z
Reserved: 2026-04-01T20:46:32.932Z
Link: CVE-2026-5386
No data.
Status : Received
Published: 2026-05-29T18:17:12.867
Modified: 2026-05-29T18:17:12.867
Link: CVE-2026-5386
No data.
OpenCVE Enrichment
No data.