PatchSiren

Xiongmai CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Xiongmai CVE published 2026-09-11

CVE-2026-79396

CVE-2026-79396 debrief based on the supplied source corpus. The vulnerability involves hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier, stored in unencrypted plaintext within bin/config.xml and compiled into the Sofia executable. This allows remote attackers to gain full administrative control over the camera. Defenders should verify firmware versions [truncated]

CRITICAL Xiongmai CVE published 2026-09-11

CVE-2026-79395

CVE-2026-79395 is a critical vulnerability in Xiongmai IP Camera XM530 firmware that allows remote attackers to bypass authentication and execute privileged ONVIF actions. The vulnerability is caused by an improper authentication routine in the Sofia IPC daemon. A crafted SOAP request can bypass authentication when the account's stored password is empty. Defenders should prioritize verifying and patching [truncated]

Review Xiongmai CVE published 2026-09-11

CVE-2026-79394

CVE-2026-79394 debrief based on the supplied source corpus. The vulnerability is an insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier. This allows remote unauthenticated attackers to access live H.264 video and G.711 audio feeds in cleartext over unencrypted RTP/UDP. Defenders should ass [truncated]

HIGH Xiongmai CVE published 2026-09-11

CVE-2026-79393

A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to cause a denial of service or potentially execute arbitrary code via a crafted SOAP request containing a wsa5:Action string exceeding 128 bytes.