Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-79394

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

雄迈 IP 摄像头 XM530(固件版本 HMT.CM2005-v220608.1837 及更早版本)中,Sofia IPC 守护进程内嵌的 Happytime RTSP 服务器存在不安全的默认配置:系统出厂时未启用身份验证,使得未认证的远程攻击者能够通过未加密的 RTP/UDP 通道,以明文方式访问实时的 H.264 视频流和 G.711 音频流。

AI Predicted 7.5 Difficulty: Trivial

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
n/a n/a n/a affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-79394

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
An insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier ships with authentication disabled, allowing remote unauthenticated attackers to access live H.264 video and G.711 audio feeds in cleartext over unencrypted RTP/UDP.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2026-79394

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-79394

登录查看更多情报信息。

Proof of Concept for CVE-2026-79394 (1)

Same Patch Batch · n/a · 2026-09-11 · 10 CVEs total

CVE-2026-71641 EGO-Planner-v2交互缺陷致服务拒绝
CVE-2026-71644 RACER FSM缺失默认分支致无人机碰撞
CVE-2026-78807 wpa_supplicant <2.12 PMKSA缓存验证缺失
CVE-2026-71646 RACER abcdef1234版FastExplorationFSM拒绝服务漏洞
CVE-2025-69904 Linkstack v4.8.4及更早版本路径遍历漏洞
CVE-2026-79393 雄迈IPC Sofia服务堆溢出漏洞
CVE-2026-79395 雄迈相机IPC鉴权缺陷
CVE-2026-79396 雄迈IP摄像机XM530默认凭据硬编码
CVE-2026-79362 WCF 6.1.0-6.1.23/6.2.0-6.2.6 缓存投毒RCE

IV. Related Vulnerabilities

V. Comments for CVE-2026-79394

No comments yet


Leave a comment