Impact
A heap-based buffer overflow exists in the WS‑Addressing Action transformation within the Sofia IPC daemon of Xiongmai IP Camera XM530 firmware HMT.CM2005‑v220608.1837 and earlier. A crafted SOAP request containing a wsa5:Action string longer than 128 bytes can trigger the overflow, allowing an attacker to either cause a denial of service or potentially execute arbitrary code on the device.
Affected Systems
The vulnerability affects Xiongmai IP Camera XM530 models running firmware HMT.CM2005‑v220608.1837 and earlier. No other vendors or product lines are listed as affected.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity issue with significant impact. The EPSS score of <1% suggests a very low likelihood of exploitation, and the vulnerability is not listed in KEV. The vector is remote, unauthenticated, and requires the ability to send SOAP requests to the IPC daemon over the network; no credentials or privilege escalation are needed. Successful exploitation could lead to service disruption or code execution with the privileges the daemon runs under.
OpenCVE Enrichment