Executive brief
Xiongmai IP Camera XM530 is a network surveillance device used to capture and stream video over corporate or residential networks. The camera ships with fixed, universally-known default login credentials (admin/admin and user/123456) that are stored unencrypted in the firmware and cannot be removed. An attacker on the network can use these credentials to gain complete administrative control over any affected camera, enabling unauthorized video access, stream manipulation, or use of the device as a foothold for further network attacks.
Technical details
This vulnerability stems from the use of hardcoded default credentials (CWE-798, CWE-1392) stored in plaintext across two locations: the unencrypted rootfs bin/config.xml file and compiled directly into the Sofia IPC daemon binary. The credentials (admin/admin and user/123456) are identical across all devices in this product line and cannot be removed even if the config file is deleted, as the binary re-seeds them on startup. The vulnerability is exploitable over the network without authentication or user interaction; an attacker simply provides the known credentials to bypass WSSE ONVIF, RTSP Digest, or HTTP-based access controls. Confirmed through static reverse engineering and direct firmware inspection. Patch status and vendor mitigation guidance are not detailed in the advisory.
Affected products
- Xiongmai XM530 HMT.CM2005-v220608.1837 and earlier
Timeline
- 2026-09-11: disclosed