CVE-2026-79393: Buffer Overflow
A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to cause a denial of service or potentially execute arbitrary code via a crafted SOAP request containing a wsa5:Action string exceeding 128 bytes.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
An attacker can exploit the vulnerability remotely without authentication by sending a crafted SOAP request to the affected Sofia IPC daemon. The request must include a wsa5:Action string longer than 128 bytes.
Which firmware versions are known to be affected?
Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier is identified as affected.
What is the likely impact of successful exploitation?
Successful exploitation can cause a denial of service and may potentially allow arbitrary code execution because the vulnerable WS-Addressing Action transformation function has a heap-based buffer overflow.