CVE-2026-79393 Details
Description
A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to cause a denial of service or potentially execute arbitrary code via a crafted SOAP request containing a wsa5:Action string exceeding 128 bytes.
A heap-based buffer overflow vulnerability has been identified in the WS-Addressing Action transformation function of the Sofia IPC daemon, present in Xiongmai IP Camera XM530 firmware versions HMT.CM2005-v220608.1837 and earlier. This vulnerability allows remote, unauthenticated attackers to cause a denial-of-service or potentially execute arbitrary code by sending a crafted SOAP request with a wsa5:Action string longer than 128 bytes. The issue arises because the ONVIF HTTP server deserializes the WS-Addressing header without authentication, leading to memory corruption that can be exploited.
To address this vulnerability, it is recommended to enforce a length check on the WS-Addressing Action element before processing it. Additionally, rebuilding the application with stack canaries and enabling the RELRO option can help mitigate the risk of exploitation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 11, 2026CISA-ADP
Assessed Sep 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ShiroiBoushi/vulnerability-research/tree/main/CVE-2026-79393 | [email protected] | ExploitTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-122 | Heap-based Buffer Overflow | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Xiongmai Sofia | <= HMT.CM2005-v210104.1124 <= HMT.CM2005-v220608.1837 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 11, 2026 | New CVE Received | [email protected] |
| Sep 11, 2026 | CVE Modified | CISA-ADP |
Volerion