CVE 7.2 HIGH

H.VIEW HV-500S6 IP Camera OS Command Injection_CVE-2026-55975

7.2 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Description

A vulnerability exists in H.View IP cameras that could allow an authenticated user to supply unsanitized XML fields to the device's certificate generation interface, which are incorporated into a backend certificate creation command without proper input validation. This may allow for command execution with elevated privileges during certificate generation.

Basic Information

ID CVE-2026-55975
Source icscert
Published Jun 26, 2026 at 22:58

Affected Product

Vendor H.VIEW
Product HV-500S6 IP Camera
Version IPCAM_V4.06.88.251229
Affected Versions H.VIEW HV-500S6 IP Camera IPCAM_V4.06.88.251229

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.