PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-5386 KMW CVE debrief

A critical unauthenticated password reset vulnerability in KMW CCTV Security Cameras allows remote attackers to reset the administrator password without authentication, granting full access to camera feeds and settings. The vulnerability carries a CVSS 3.1 score of 9.1 (Critical) with network attack vector, low attack complexity, no privileges required, and no user interaction needed. The weakness is categorized as CWE-620: Unverified Password Change. CISA published advisory ICSA-26-148-06 on May 29, 2026, and the vendor has released firmware updates to address this issue.

Vendor
KMW
Product
KM-IP521
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-28
Original CVE updated
2026-05-28
Advisory published
2026-05-28
Advisory updated
2026-05-28

Who should care

Organizations deploying KMW CCTV Security Cameras in physical security, critical infrastructure, or sensitive environments should prioritize patching. Security teams responsible for OT/ICS networks, facility management, and surveillance systems must assess exposure and apply mitigations immediately.

Technical summary

The vulnerability exists in KMW CCTV Security Cameras and allows unauthenticated remote attackers to reset the administrator password to a known value. Successful exploitation grants complete administrative control over the device, including access to live camera feeds, recorded footage, and all configuration settings. The attack requires no authentication credentials and can be executed remotely over the network. The underlying weakness is CWE-620 (Unverified Password Change), indicating the password reset functionality fails to verify the identity of the requester before allowing password modification.

Defensive priority

critical

Recommended defensive actions

  • Immediately apply firmware updates from the vendor to affected KMW CCTV Security Camera models
  • Restrict network access to camera management interfaces using firewall rules or network segmentation
  • Monitor for unauthorized password reset attempts or configuration changes in camera logs
  • Verify administrator account integrity and reset credentials if compromise is suspected
  • Review camera access logs for unauthorized administrative access since May 29, 2026

Evidence notes

Vulnerability disclosed via CISA ICS advisory ICSA-26-148-06. CVSS vector confirms network-exploitable, unauthenticated attack with high impact on confidentiality and integrity. Firmware update available from vendor.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-5386 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-5386

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-5386 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-5386

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.