CVE-2026-56414 Details
Description
A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arbitrary file content to fixed, persistent filesystem locations without validating file type, structure, or size. This design omission enables the placement of unexpected or malformed data in locations intended for trusted certificate material, which could affect system integrity or behavior even after reboot.
A vulnerability in H.View IP cameras' certificate-related upload interfaces allows authenticated users to upload arbitrary files to specific, permanent locations on the device's filesystem. This upload process lacks proper validation of file type, structure, or size. As a result, unexpected or malformed data can be placed in areas designated for trusted certificate materials, potentially disrupting system integrity or functionality, even after a reboot.
H.View has not responded to CISA's request for coordination. Users are encouraged to contact H.View for support via their official website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 26, 2026CISA-ADP
Assessed Jun 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-176-05.json | [email protected] | AdvisoryBundleRemedy |
| https://hviewsmart.com/pages/contact-us | [email protected] | Vendor |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-05 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| H.View HV-500S6 | IPCAM_V4.06.88.251229 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 29, 2026 | CVE Modified | CISA-ADP |
| Jun 26, 2026 | New CVE Received | [email protected] |
Volerion