Executive brief
Xiongmai IP cameras use a SOAP-based authentication system to control camera features such as live video streaming, pan/tilt/zoom controls, and system reboots. A flaw in the authentication verification allows an attacker to bypass login by sending a specially crafted request with the default admin username and any arbitrary password, granting full control of the camera without a valid account.
Technical details
The vulnerability is an improper authentication flaw (CWE-287) in the Sofia IPC daemon's WS-Security UsernameToken verifier. When a user account has an empty stored password, the verifier explicitly accepts any supplied password and skips SHA-1 digest validation entirely. An unauthenticated remote attacker can exploit this via a single SOAP request containing the admin username with any arbitrary password, bypassing authentication and gaining full access to privileged ONVIF operations including PTZ control, video stream retrieval, and system reboot. The attack requires only network reachability and knowledge of a default username; no prior authentication is needed. The vulnerability has been verified in firmware HMT.CM2005-v220608.1837 and earlier through both static analysis and live testing.
Affected products
- Xiongmai IP Camera XM530 HMT.CM2005-v220608.1837 and earlier
Timeline
- 2026-09-11: disclosed