CVE-2026-79394
EUVD-2026-7619011.09.2026, 19:17
An insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier ships with authentication disabled, allowing remote unauthenticated attackers to access live H.264 video and G.711 audio feeds in cleartext over unencrypted RTP/UDP.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.