CVE-2026-5386 Details
Description
The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password to a known value without authentication, granting full access to the camera feeds and settings.
A critical vulnerability allowing unauthenticated password resets has been identified in KMW CCTV Security Cameras, specifically in the KM-IP521 and KM-IP421 models. This flaw enables an attacker to remotely reset the administrator password to a known value, thereby gaining full access to the camera feeds and settings.
KMW has released a firmware update to address this vulnerability, available for download on the KMW website. Users of the KM-IP421 model will need to contact customer support to re-authorize their P2P connection after the update.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 29, 2026CISA-ADP
Assessed May 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-148-06.json | [email protected] | AdvisoryBundleRemedy |
| https://main.kmw.ro/pub/Firmware/521_421.zip | [email protected] | Broken LinkVendor |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-148-06 | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-620 | Unverified Password Change | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| KMW KM-IP521 | IPCAM_V4.04.91.230307 |
CPE
Remediation
| |
| KMW KM-IP421 | IPCAM_V4.04.53.210416 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 29, 2026 | New CVE Received | [email protected] |
Volerion