Description
A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to cause a denial of service or potentially execute arbitrary code via a crafted SOAP request containing a wsa5:Action string exceeding 128 bytes.
Published: 2026-09-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

A heap-based buffer overflow exists in the WS‑Addressing Action transformation within the Sofia IPC daemon of Xiongmai IP Camera XM530 firmware HMT.CM2005‑v220608.1837 and earlier. A crafted SOAP request containing a wsa5:Action string longer than 128 bytes can trigger the overflow, allowing an attacker to either cause a denial of service or potentially execute arbitrary code on the device.

Affected Systems

The vulnerability affects Xiongmai IP Camera XM530 models running firmware HMT.CM2005‑v220608.1837 and earlier. No other vendors or product lines are listed as affected.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity issue with significant impact. The EPSS score of <1% suggests a very low likelihood of exploitation, and the vulnerability is not listed in KEV. The vector is remote, unauthenticated, and requires the ability to send SOAP requests to the IPC daemon over the network; no credentials or privilege escalation are needed. Successful exploitation could lead to service disruption or code execution with the privileges the daemon runs under.

Generated by OpenCVE AI on September 21, 2026 at 04:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the camera firmware to a version newer than HMT.CM2005‑v220608.1837, if an upgrade is available.
  • Restrict network access to the camera’s SOAP interface by permitting only trusted IP addresses or by using firewall rules.
  • Configure a frontend filter or WAF to block SOAP requests whose wsa5:Action string exceeds 128 bytes before they reach the IPC daemon.

Generated by OpenCVE AI on September 21, 2026 at 04:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in Xiongmai IPC Daemon

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Xiongmai
Xiongmai ip Camera Xm530
Vendors & Products Xiongmai
Xiongmai ip Camera Xm530

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to cause a denial of service or potentially execute arbitrary code via a crafted SOAP request containing a wsa5:Action string exceeding 128 bytes.
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Xiongmai Ip Camera Xm530
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-11T18:49:39.373Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-79393

cve-icon Vulnrichment

Updated: 2026-09-11T18:49:34.996Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T19:17:46.070

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-79393

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:45:09Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow