Executive brief
Xiongmai XM530 IP cameras ship with the embedded RTSP server configured without authentication by default, allowing anyone on the network to view live video and audio streams without a password. An attacker can remotely access unencrypted video and audio feeds, potentially exposing sensitive surveillance data and compromising physical security monitoring systems.
Technical details
The Sofia IPC daemon in Xiongmai XM530 firmware bundles a Happytime RTSP server with authentication disabled by default. The vulnerability allows unauthenticated remote attackers to connect to the RTSP service (default ports 554/TCP and RTP/UDP) and receive live H.264 video and G.711 audio streams in cleartext. No authentication credentials are required and no user interaction is needed; a simple network connection to the camera is sufficient. Attackers can capture surveillance footage and audio, potentially monitoring premises, personnel, and sensitive operations. The issue affects firmware version HMT.CM2005-v220608.1837 and earlier.
Affected products
- Xiongmai XM530 HMT.CM2005-v220608.1837 and earlier
Timeline
- 2026-09-11: disclosed: CVE-2026-79394 published