Impact
The firmware of the Xiongmai IP Camera XM530 contains hardcoded default credentials that are stored in plaintext within bin/config.xml and compiled into the Sofia executable. These static account credentials allow a remote attacker to authenticate as a full administrator, gaining complete control over the device and all data it handles. The vulnerability enables an attacker to view confidential camera feeds, change configuration settings, and potentially access the network resources to which the camera is connected.
Affected Systems
The vulnerable devices are Xiongmai IP Cameras of the XM530 model that run firmware HMT.CM2005-v220608.1837 and earlier. These cameras ship with the default credentials hardcoded in the firmware, which remains unchanged across the affected releases.
Risk and Exploitability
The EPSS score is < 1%, indicating low probability of exploitation, and the CVE is not listed in the CISA KEV database. Nevertheless, any network-accessible attacker can read the configuration file or the executable, extract the hardcoded credentials, and authenticate as a full administrator, giving them complete control of the camera and its network.
OpenCVE Enrichment