An insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier ships with authentication disabled, allowing remote unauthenticated attackers to access live H.264 video and G.711 audio feeds in cleartext over unencrypted RTP/UDP.

Project Subscriptions

Vendors Products
Xiongmai Subscribe
Ip Camera Xm530 Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1188
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Xiongmai
Xiongmai ip Camera Xm530
Vendors & Products Xiongmai
Xiongmai ip Camera Xm530

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description An insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier ships with authentication disabled, allowing remote unauthenticated attackers to access live H.264 video and G.711 audio feeds in cleartext over unencrypted RTP/UDP.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-15T15:18:49.618Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-79394

cve-icon Vulnrichment

Updated: 2026-09-15T15:18:38.911Z

cve-icon NVD

Status : Received

Published: 2026-09-11T19:17:46.247

Modified: 2026-09-15T16:17:26.580

Link: CVE-2026-79394

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:57:21Z

Weaknesses