CVE-2026-79394: Sofia IPC Happytime RTSP server (embedded) vulnerability
An insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier ships with authentication disabled, allowing remote unauthenticated attackers to access live H.264 video and G.711 audio feeds in cleartext over unencrypted RTP/UDP.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Enable authentication on the embedded Happytime RTSP server within the Sofia IPC daemon to prevent remote unauthenticated access to live H.264 and G.711 feeds.
Sofia IPC daemon (embedded Happytime RTSP server) authentication = enabled - Compensating control
Ensure RTSP/RTP video/audio streams are not accessible over unencrypted RTP/UDP from untrusted networks (e.g., restrict network access to trusted clients only).
Event History
Frequently Asked Questions
Which deployments are exposed by default?
Devices running the embedded Happytime RTSP server in the Sofia IPC daemon are exposed when using XM530 firmware HMT.CM2005-v220608.1837 or earlier, because the server ships with authentication disabled.
What does an attacker need to access the camera feeds?
A remote attacker needs network access to the RTSP service. No authentication is required under the affected default configuration.
What data can be exposed?
An attacker can access live H.264 video and G.711 audio feeds. The feeds are transmitted in cleartext over unencrypted RTP/UDP.