CVE 7.2 HIGH

H.VIEW HV-500S6 IP Camera Unrestricted Upload of File with Dangerous Type_CVE-2026-56414

7.2 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Description

A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arbitrary file content to fixed, persistent filesystem locations without validating file type, structure, or size. This design omission enables the placement of unexpected or malformed data in locations intended for trusted certificate material, which could affect system integrity or behavior even after reboot.

Basic Information

ID CVE-2026-56414
Source icscert
Published Jun 26, 2026 at 23:00

Affected Product

Vendor H.VIEW
Product HV-500S6 IP Camera
Version IPCAM_V4.06.88.251229
Affected Versions H.VIEW HV-500S6 IP Camera IPCAM_V4.06.88.251229

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.