Sceawere

Vulnerability Detail

CVE-2026-79395UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Sofia IPC Improper Authentication Bypass

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
5h ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass authentication and execute privileged ONVIF actions (including PTZ control, stream URL retrieval, and system reboot) via a crafted SOAP request supplying the admin username with any arbitrary password when the account's stored password is empty.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-09-11T19:17:46.367Z",
  "pubdate": "2026-09-11T19:17:46.367Z",
  "executiveSummary": "An improper authentication vulnerability exists within the WS-Security verification mechanism of the Sofia IPC daemon found in Xiongmai IP Camera XM530 firmware.\nThis vulnerability is classified as an authentication bypass that permits unauthorized remote actors to assume the privileges of the administrative account.\nThe flaw specifically affects devices running firmware version HMT.CM2005-v220608.1837 and earlier, posing a critical security risk to internal and perimeter surveillance infrastructure.\nBy manipulating the SOAP authentication handshake, an attacker can bypass traditional password validation protocols provided the device's administrator account has not been assigned a specific password.\nThe successful exploitation of this flaw grants an attacker full control over ONVIF-based operations, including sensitive camera movements, retrieval of live stream URLs, and the capability to perform unauthorized system reboots.\nThis vulnerability stems from a logical failure in the wsse:UsernameToken validation routine, which fails to enforce strict authentication integrity when the stored password state is null or empty.\nGiven the nature of IP camera deployments, this risk profile is elevated for devices exposed to network interfaces without additional access control layers.",
  "technicalDetails": "The vulnerability resides within the Sofia IPC daemon responsible for processing ONVIF SOAP requests. Specifically, the flaw exists in the verification logic governing the wsse:UsernameToken header, an industry-standard mechanism for implementing message-level security in XML-based web services.\nThe root cause of the vulnerability is a logic error in the credential validation function. During the processing of the SOAP header, the daemon checks the provided wsse:UsernameToken against the system-stored credentials. When the administrative user account has no password configured (a default or neglected state), the verification routine fails to perform a rigorous comparison, effectively treating an arbitrary or blank password as a successful match.\nThe exploitation flow begins with the attacker crafting a specially formulated SOAP request directed at the camera's ONVIF endpoint. The request must include a wsse:UsernameToken element specifying the 'admin' username. Because the vulnerable code path incorrectly handles the empty password state, the attacker can supply any arbitrary string within the password field or leave it blank, causing the backend service to validate the session as authenticated.\nOnce the authentication bypass is successful, the attacker can issue privileged ONVIF commands that the Sofia IPC daemon processes as legitimate requests. This includes, but is not limited to, interacting with the PTZ (Pan-Tilt-Zoom) controller to reorient the camera, querying system configuration files to retrieve sensitive stream URLs, or sending diagnostic commands to trigger a device reboot.\nThe impact is significant as it allows for persistent unauthorized observation and denial-of-service via system manipulation. The vulnerability is exploitable remotely over the network, provided the ONVIF service is reachable. Because this is a logic flaw in the authentication handling of the SOAP protocol itself, no prior session tokens or valid credentials are required for the initial entry.\nThe vulnerability is present in Xiongmai IP Camera XM530 firmware versions up to and including HMT.CM2005-v220608.1837. The failure to validate credentials securely when the password field is null indicates an oversight in the error-handling or conditional branching logic of the daemon's authentication module."
}
CVE-2026-79395: Sofia IPC Improper Authentication Bypass (CRITICAL Severity, CVSS: 9.8) | Sceawere