Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-79395

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Xiongmai(雄迈)IP 摄像头 XM530 固件版本 HMT.CM2005-v220608.1837 及更早版本中的 Sofia IPC 守护进程在 WS-Security(wsse:UsernameToken)验证例程中存在身份验证不当的漏洞。当账户存储的密码为空时,远程攻击者可以通过构造一个提供管理员用户名和任意密码的 SOAP 请求来绕过身份验证,并执行特权 ONVIF 操作(包括 PTZ 控制、流 URL 获取和系统重启)。

AI Predicted 7.5 Difficulty: Easy

Possible ATT&CK Techniques 1 AI

T1083.004

Affected Version Matrix 1

VendorProduct Version RangeStatus
n/a n/a n/a affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-79395

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass authentication and execute privileged ONVIF actions (including PTZ control, stream URL retrieval, and system reboot) via a crafted SOAP request supplying the admin username with any arbitrary password when the account's stored password is empty.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2026-79395

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-79395

登录查看更多情报信息。

Other References for CVE-2026-79395 (1)

Same Patch Batch · n/a · 2026-09-11 · 10 CVEs total

CVE-2026-71641 EGO-Planner-v2交互缺陷致服务拒绝
CVE-2026-71644 RACER FSM缺失默认分支致无人机碰撞
CVE-2026-78807 wpa_supplicant <2.12 PMKSA缓存验证缺失
CVE-2026-71646 RACER abcdef1234版FastExplorationFSM拒绝服务漏洞
CVE-2025-69904 Linkstack v4.8.4及更早版本路径遍历漏洞
CVE-2026-79393 雄迈IPC Sofia服务堆溢出漏洞
CVE-2026-79394 雄迈摄像头XM530 RTSP服务默认禁用认证致数据泄露
CVE-2026-79396 雄迈IP摄像机XM530默认凭据硬编码
CVE-2026-79362 WCF 6.1.0-6.1.23/6.2.0-6.2.6 缓存投毒RCE

IV. Related Vulnerabilities

V. Comments for CVE-2026-79395

No comments yet


Leave a comment