CVE-2026-79396: Xiongmai IP Camera XM530 vulnerability
Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores static account credentials in unencrypted plaintext within bin/config.xml and compiled into the Sofia executable, allowing remote attackers to gain full administrative control over the camera.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Xiongmai IP Camera XM530 firmwareto a version that resolves this vulnerability.Fixed in HMT.CM2005-v220608.1837 - Compensating control
Restrict network access to the camera so remote attackers cannot reach the camera’s administration interface (e.g., limit access to trusted IPs only at the firewall).
Event History
Frequently Asked Questions
How can I determine whether a camera is affected?
Prioritize Xiongmai IP Camera XM530 devices running firmware HMT.CM2005-v220608.1837 or earlier.
What access could an attacker obtain?
A remote attacker could gain full administrative control of the affected camera.