Impact
An insecure default configuration in the embedded Happytime RTSP server of the Sofia IPC daemon within the Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows authentication to be bypassed, enabling any actor with network connectivity to retrieve live H.264 video and G.711 audio feeds in cleartext over unencrypted RTP/UDP. The flaw represents an improper authorization weakness (CWE-1188) that exposes confidential surveillance data without requiring credentials or encryption.
Affected Systems
The vulnerability affects the Xiongmai IP Camera model XM530 running firmware HMT.CM2005-v220608.1837 and earlier. Cameras with firmware revisions that enable authentication for the Happytime RTSP service are not affected.
Risk and Exploitability
The CVSS score of 7.5 rates the flaw as high severity, and the EPSS score of less than 1% indicates a low probability of exploitation overall; however, since authentication is disabled by default, any successful connection yields immediate access to unencrypted surveillance streams. The vulnerability is not listed in CISA’s KEV catalog. Attackers likely initiate the exploit by sending standard RTSP requests over UDP to the camera’s IP address, typically targeting port 554.
OpenCVE Enrichment