CVE-2026-79396 Details
Description
Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores static account credentials in unencrypted plaintext within bin/config.xml and compiled into the Sofia executable, allowing remote attackers to gain full administrative control over the camera.
A vulnerability exists in Xiongmai IP cameras running the Sofia IPC camera daemon, specifically in the firmware version HMT.CM2005-v220608.1837 and earlier. This vulnerability arises from hardcoded default credentials that are identical across all cameras in the product line. The credentials, 'admin' with password 'admin' and 'user' with password '123456', are stored in unencrypted plaintext within the root filesystem's config.xml file and are also embedded in the Sofia executable. This allows remote attackers to gain full administrative control over the cameras.
To address this vulnerability, it is recommended to implement unique credentials for each device at the time of provisioning, remove hardcoded credential seeding from the Sofia binary, hash stored passwords in the config.xml file, and ensure that authentication is enabled by default on all devices.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 11, 2026CISA-ADP
Assessed Sep 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ShiroiBoushi/vulnerability-research/tree/main/CVE-2026-79396 | CISA-ADP | ExploitTechnical Analysis |
| https://github.com/ShiroiBoushi/vulnerability-research/tree/main/CVE-2026-79396 | [email protected] | ExploitTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Xiongmai IP Camera XM530 | >= HMT.CM2005-v210104.1124, <= HMT.CM2005-v220608.1837 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 14, 2026 | CVE Modified | CISA-ADP |
| Sep 11, 2026 | New CVE Received | [email protected] |
Volerion