Description
Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores static account credentials in unencrypted plaintext within bin/config.xml and compiled into the Sofia executable, allowing remote attackers to gain full administrative control over the camera.
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Administrative Control
Action: Immediate Patch
AI Analysis

Impact

The firmware of the Xiongmai IP Camera XM530 contains hardcoded default credentials that are stored in plaintext within bin/config.xml and compiled into the Sofia executable. These static account credentials allow a remote attacker to authenticate as a full administrator, gaining complete control over the device and all data it handles. The vulnerability enables an attacker to view confidential camera feeds, change configuration settings, and potentially access the network resources to which the camera is connected.

Affected Systems

The vulnerable devices are Xiongmai IP Cameras of the XM530 model that run firmware HMT.CM2005-v220608.1837 and earlier. These cameras ship with the default credentials hardcoded in the firmware, which remains unchanged across the affected releases.

Risk and Exploitability

The EPSS score is < 1%, indicating low probability of exploitation, and the CVE is not listed in the CISA KEV database. Nevertheless, any network-accessible attacker can read the configuration file or the executable, extract the hardcoded credentials, and authenticate as a full administrator, giving them complete control of the camera and its network.

Generated by OpenCVE AI on September 21, 2026 at 04:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the camera to the latest firmware where hardcoded default credentials have been removed and credentials are stored securely.
  • If no firmware update is available, immediately change the camera’s default username and password through the web interface to lock out attackers.
  • Restrict remote management by placing the camera on a segmented network, disabling exposure of management ports to the Internet, and using firewall rules to limit access to trusted IP addresses.

Generated by OpenCVE AI on September 21, 2026 at 04:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-798
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Xiongmai
Xiongmai ip Camera Xm530
Vendors & Products Xiongmai
Xiongmai ip Camera Xm530

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores static account credentials in unencrypted plaintext within bin/config.xml and compiled into the Sofia executable, allowing remote attackers to gain full administrative control over the camera.
References

Subscriptions

Xiongmai Ip Camera Xm530
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T18:54:21.156Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-79396

cve-icon Vulnrichment

Updated: 2026-09-14T18:54:00.806Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T19:17:46.480

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-79396

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:45:09Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials