Description
An insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier ships with authentication disabled, allowing remote unauthenticated attackers to access live H.264 video and G.711 audio feeds in cleartext over unencrypted RTP/UDP.
Published: 2026-09-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote unauthenticated access to live video and audio streams
Action: Patch Firmware
AI Analysis

Impact

An insecure default configuration in the embedded Happytime RTSP server of the Sofia IPC daemon within the Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows authentication to be bypassed, enabling any actor with network connectivity to retrieve live H.264 video and G.711 audio feeds in cleartext over unencrypted RTP/UDP. The flaw represents an improper authorization weakness (CWE-1188) that exposes confidential surveillance data without requiring credentials or encryption.

Affected Systems

The vulnerability affects the Xiongmai IP Camera model XM530 running firmware HMT.CM2005-v220608.1837 and earlier. Cameras with firmware revisions that enable authentication for the Happytime RTSP service are not affected.

Risk and Exploitability

The CVSS score of 7.5 rates the flaw as high severity, and the EPSS score of less than 1% indicates a low probability of exploitation overall; however, since authentication is disabled by default, any successful connection yields immediate access to unencrypted surveillance streams. The vulnerability is not listed in CISA’s KEV catalog. Attackers likely initiate the exploit by sending standard RTSP requests over UDP to the camera’s IP address, typically targeting port 554.

Generated by OpenCVE AI on September 21, 2026 at 04:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the camera firmware to a revision that requires authentication for the Happytime RTSP service
  • Restrict inbound RTP/UDP traffic by configuring the camera’s firewall or network ACLs to allow only trusted local networks
  • Place the camera behind a VPN or secure network segment to limit exposure until the firmware can be updated
  • Monitor network traffic for unencrypted RTP/UDP streams and generate alerts on anomalous activity

Generated by OpenCVE AI on September 21, 2026 at 04:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access to Unencrypted RTSP Streams in Xiongmai IP Camera Firmware

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1188
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Xiongmai
Xiongmai ip Camera Xm530
Vendors & Products Xiongmai
Xiongmai ip Camera Xm530

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description An insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier ships with authentication disabled, allowing remote unauthenticated attackers to access live H.264 video and G.711 audio feeds in cleartext over unencrypted RTP/UDP.
References

Subscriptions

Xiongmai Ip Camera Xm530
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-15T15:18:49.618Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-79394

cve-icon Vulnrichment

Updated: 2026-09-15T15:18:38.911Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T19:17:46.247

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-79394

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:45:09Z

Weaknesses
  • CWE-1188

    Initialization of a Resource with an Insecure Default