Junglewise Threat Intelligence

CVE-2026-56414: H.VIEW HV-500S6 IP Camera unrestricted file upload in certificate interface

CVE-2026-56414 · Severity: high · CVSS 7.2 · Published 2026-06-26

Executive brief

H.VIEW IP cameras, which are used for security monitoring in commercial and residential settings, contain a vulnerability in their certificate management interface. An authorized user with high-level permissions can upload malicious files to the camera's permanent storage. This could allow an attacker to compromise the device's integrity, potentially leading to persistent unauthorized access or disruption of the surveillance system that remains even after the device is restarted.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in the certificate-related upload interfaces of H.VIEW HV-500S6 IP cameras. The application fails to validate file type, structure, or size when processing uploads intended for trusted certificate material. An authenticated attacker with high privileges can exploit this to write arbitrary data to fixed, persistent filesystem locations. This design omission can be used to place malformed or malicious data on the device, affecting system behavior and integrity across reboots. As of the advisory date, the vendor has not responded to coordination efforts, and no official patch is available.

Affected products

  • H.VIEW HV-500S6 IP Camera IPCAM_V4.06.88.251229

Timeline

  • 2026-06-25: advisory: CISA published ICSA-26-176-05
  • 2026-06-26: disclosed: NVD published CVE-2026-56414

References

Related threats