An insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier ships with authentication disabled, allowing remote unauthenticated attackers to access live H.264 video and G.711 audio feeds in cleartext over unencrypted RTP/UDP.
CVE-2026-79394
NONE
EPSS 0.22%
Updated Sep 11, 2026
An
CVE Details
CVE ID
CVE-2026-79394
Published Date
Sep 11, 2026
Vendor
An
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.22%
Likelihood of exploitation in next 30 days
Percentile:
13.1th percentile (higher than 13.1% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory