PatchSiren cyber security CVE debrief
CVE-2026-5386 KMW CVE debrief
A critical unauthenticated password reset vulnerability in KMW CCTV Security Cameras allows remote attackers to reset the administrator password without authentication, granting full access to camera feeds and settings. The vulnerability carries a CVSS 3.1 score of 9.1 (Critical) with network attack vector, low attack complexity, no privileges required, and no user interaction needed. The weakness is categorized as CWE-620: Unverified Password Change. CISA published advisory ICSA-26-148-06 on May 29, 2026, and the vendor has released firmware updates to address this issue.
- Vendor
- KMW
- Product
- KM-IP521
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-28
- Original CVE updated
- 2026-05-28
- Advisory published
- 2026-05-28
- Advisory updated
- 2026-05-28
Who should care
Organizations deploying KMW CCTV Security Cameras in physical security, critical infrastructure, or sensitive environments should prioritize patching. Security teams responsible for OT/ICS networks, facility management, and surveillance systems must assess exposure and apply mitigations immediately.
Technical summary
The vulnerability exists in KMW CCTV Security Cameras and allows unauthenticated remote attackers to reset the administrator password to a known value. Successful exploitation grants complete administrative control over the device, including access to live camera feeds, recorded footage, and all configuration settings. The attack requires no authentication credentials and can be executed remotely over the network. The underlying weakness is CWE-620 (Unverified Password Change), indicating the password reset functionality fails to verify the identity of the requester before allowing password modification.
Defensive priority
critical
Recommended defensive actions
- Immediately apply firmware updates from the vendor to affected KMW CCTV Security Camera models
- Restrict network access to camera management interfaces using firewall rules or network segmentation
- Monitor for unauthorized password reset attempts or configuration changes in camera logs
- Verify administrator account integrity and reset credentials if compromise is suspected
- Review camera access logs for unauthorized administrative access since May 29, 2026
Evidence notes
Vulnerability disclosed via CISA ICS advisory ICSA-26-148-06. CVSS vector confirms network-exploitable, unauthenticated attack with high impact on confidentiality and integrity. Firmware update available from vendor.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-5386 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-5386
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-5386 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-5386
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-148-06.json
-
Source reference
Unverified legacy reference
URL: https://main.kmw.ro/pub/Firmware/521_421.zip
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-148-06
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.