PatchSiren cyber security CVE debrief
CVE-2026-79394 Xiongmai CVE debrief
CVE-2026-79394 debrief based on the supplied source corpus. The vulnerability is an insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier. This allows remote unauthenticated attackers to access live H.264 video and G.711 audio feeds in cleartext over unencrypted RTP/UDP. Defenders should assess exposure and verify configurations to prevent unauthorized access. The CVE record and NVD entry provide details on this vulnerability.
- Vendor
- Xiongmai
- Product
- Xiongmai IP Camera XM530
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-11
- Original CVE updated
- 2026-09-11
- Advisory published
- 2026-09-11
- Advisory updated
- 2026-09-11
Who should care
Defenders responsible for IP camera systems, particularly those using Xiongmai IP Camera XM530 firmware, should assess exposure and verify configurations to prevent unauthorized access.
Why it matters
CVE-2026-79394 is a vulnerability in the Xiongmai IP Camera XM530 firmware that allows remote unauthenticated access to live video and audio feeds. Defenders should verify IP camera configurations, limit access to authorized personnel, and monitor for potential unauthorized access attempts.
- Potential unauthorized access to sensitive video and audio feeds
- Possible eavesdropping or surveillance by unauthorized parties
- Risk of lateral movement to adjacent systems or networks
Technical summary
The Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier has an insecure default configuration in the embedded Happytime RTSP server. This allows remote unauthenticated attackers to access live H.264 video and G.711 audio feeds in cleartext over unencrypted RTP/UDP. The vulnerability exists due to authentication being disabled by default in the RTSP server. Defenders should verify and secure IP camera configurations to prevent unauthorized access to sensitive video and audio feeds.
Defensive priority
Verify and secure IP camera configurations
Recommended defensive actions
- Verify IP camera configurations to ensure authentication is enabled for the RTSP server
- Limit access to IP camera feeds to authorized personnel only
- Monitor for and respond to potential unauthorized access attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on an insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-79394 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-79394
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-79394 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-79394
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/ShiroiBoushi/vulnerability-research/tree/main/CVE-2026-79394
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.