Executive brief
H.View IP cameras, used for security monitoring in commercial and residential settings, contain a flaw in their certificate management interface. An authorized user with high-level permissions can send specially crafted data that allows them to take full control of the camera's operating system. This could lead to unauthorized surveillance, disabling of security feeds, or using the camera as a foothold to attack other devices on the network.
Technical details
An OS command injection vulnerability (CWE-78) exists in the H.View HV-500S6 IP camera's certificate generation interface. The device fails to properly sanitize XML fields provided by the user before incorporating them into a backend shell command used for certificate creation. An authenticated attacker with high privileges (PR:H) can exploit this via network requests to execute arbitrary commands with elevated privileges on the underlying operating system. As of the advisory date, the vendor has not responded to coordination efforts, and no official patch is available; users are advised to isolate these devices from the internet and use VPNs for remote access.
Affected products
- H.VIEW HV-500S6 IP Camera IPCAM_V4.06.88.251229
Timeline
- 2026-06-25: advisory: CISA published ICSA-26-176-05
- 2026-06-26: disclosed: NVD publication date