Impact
An improper authentication flaw in the WS‑Security (wsse:UsernameToken) verification routine of the Sofia IPC daemon allows attackers to bypass all credential checks when the stored account password is empty. By sending a crafted SOAP request containing the administrative username with any arbitrary password, an attacker can gain administrative privileges and trigger privileged ONVIF actions such as pan‑tilt‑zoom control, stream URL retrieval, and system reboot. This flaw is identified as a high‑severity authentication bypass (CWE‑287).
Affected Systems
The vulnerability affects the Xiongmai IP Camera XM530 running firmware HMT.CM2005‑v220608.1837 and earlier. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity level, while the EPSS score is < 1%, suggesting a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote over the network to the camera’s SOAP endpoint; exploitation requires a common default state where the admin password is empty. Given the critical severity and the potential for unrestricted administrative control, the risk to any impacted device remains substantial and warrants immediate remediation.
OpenCVE Enrichment