CVE-2026-79394 Details
Description
An insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier ships with authentication disabled, allowing remote unauthenticated attackers to access live H.264 video and G.711 audio feeds in cleartext over unencrypted RTP/UDP.
A vulnerability exists in the embedded Happytime RTSP server within the Sofia IPC daemon of Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier. The RTSP server, which handles live video and audio streaming, is configured by default to allow unauthenticated access. This misconfiguration enables remote attackers to access H.264 video and G.711 audio feeds in cleartext over unencrypted RTP/UDP. The issue arises because the server's authentication feature is disabled by default, allowing any network client to access the streams without credentials.
To address this vulnerability, Xiongmai should change the default authentication setting to enabled, remove the hardcoded default credentials, and ensure that the RTSP server can be configured to use encryption.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 11, 2026CISA-ADP
Assessed Sep 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ShiroiBoushi/vulnerability-research/tree/main/CVE-2026-79394 | [email protected] | Technical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1188 | Initialization of a Resource with an Insecure Default | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Xiongmai Sofia | <= HMT.CM2005-v220608.1837 |
CPE
Remediation
| |
| Xiongmai XM530 | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 15, 2026 | CVE Modified | CISA-ADP |
| Sep 11, 2026 | New CVE Received | [email protected] |
Volerion