Junglewise Threat Intelligence

CVE-2026-79394: Xiongmai XM530 insecure default RTSP authentication

CVE-2026-79394 · Severity: high · CVSS 7.5 · Published 2026-09-11

Executive brief

Xiongmai XM530 IP cameras ship with the embedded RTSP server configured without authentication by default, allowing anyone on the network to view live video and audio streams without a password. An attacker can remotely access unencrypted video and audio feeds, potentially exposing sensitive surveillance data and compromising physical security monitoring systems.

Technical details

The Sofia IPC daemon in Xiongmai XM530 firmware bundles a Happytime RTSP server with authentication disabled by default. The vulnerability allows unauthenticated remote attackers to connect to the RTSP service (default ports 554/TCP and RTP/UDP) and receive live H.264 video and G.711 audio streams in cleartext. No authentication credentials are required and no user interaction is needed; a simple network connection to the camera is sufficient. Attackers can capture surveillance footage and audio, potentially monitoring premises, personnel, and sensitive operations. The issue affects firmware version HMT.CM2005-v220608.1837 and earlier.

Affected products

  • Xiongmai XM530 HMT.CM2005-v220608.1837 and earlier

Timeline

  • 2026-09-11: disclosed: CVE-2026-79394 published

References

Related threats