CVE 9.1 CRITICAL

KMW CCTV Security Cameras Unverified Password Change_CVE-2026-5386

9.1 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password to a known value without authentication, granting full access to the camera feeds and settings.

Basic Information

ID CVE-2026-5386
Source icscert
Published May 29, 2026 at 16:25

Affected Product

Vendor KMW
Product KM-IP521
Version 4.04.91.230307
Affected Versions KMW KM-IP521 4.04.91.230307
KMW KM-IP421 4.04.53.210416

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.