Executive brief
KMW CCTV security cameras are affected by a critical security flaw that allows unauthorized individuals to reset the administrator password remotely. By exploiting this vulnerability, an attacker can gain full control over the camera, including the ability to view live video feeds and modify device settings. This poses a significant risk to privacy and physical security for organizations using these cameras in commercial or government facilities.
Technical details
The vulnerability is classified as an Unverified Password Change (CWE-620) within the KMW CCTV camera firmware. It allows a remote, unauthenticated attacker to reset the administrator password to a known value without providing current credentials. The flaw affects KM-IP521 (IPCAM_V4.04.91.230307) and KM-IP421 (IPCAM_V4.04.53.210416). Successful exploitation grants the attacker full administrative privileges, enabling unauthorized access to video streams and system configuration. KMW has released a firmware update to address the issue, though users of the KM-IP421 model may require manual re-authorization of P2P connections after patching.
Affected products
- KMW KM-IP521 IPCAM_V4.04.91.230307
- KMW KM-IP421 IPCAM_V4.04.53.210416
Timeline
- 2026-05-28: advisory: CISA published advisory ICSA-26-148-06
- 2026-05-29: disclosed: CVE-2026-5386 published to NVD dataset
- 2026-05-28: patched: KMW issued firmware updates to address the vulnerability