Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
CISA Warns: Old Oracle WebLogic Flaw Two-Year-Old Server
June 2, 2026
Anthropic Expands Claude Mythos AI Preview to 1 Project Glasswing
June 2, 2026
Critical KMW CCTV Flaw Lets Attackers Vulnerability Gain
June 2, 2026
Home/CyberSecurity News/Critical KMW CCTV Flaw Lets Attackers Vulnerability Gain
CyberSecurity News

Critical KMW CCTV Flaw Lets Attackers Vulnerability Gain

Attackers could gain full, unauthorized access to live camera feeds and device settings on KMW CCTV security cameras, thanks to a newly identified critical security flaw. The vulnerability, tracked...

Marcus Rodriguez
Marcus Rodriguez
June 2, 2026 2 Min Read
1 0

Attackers could gain full, unauthorized access to live camera feeds and device settings on KMW CCTV security cameras, thanks to a newly identified critical security flaw.

The vulnerability, tracked as CVE-2026-5386, has been assigned a high CVSS v3 score of 9.1, highlighting its severe impact on organizations relying on these surveillance systems.

The issue stems from an “unverified password change” weakness in affected devices, which allows remote attackers to modify authentication credentials without proper validation.

Once exploited, threat actors can take control of the camera, view real-time video streams, alter configurations, or potentially turn off surveillance operations altogether.

This creates significant security risks, particularly in sensitive environments where CCTV systems play a critical role in monitoring and safety.

KMW CCTV Vulnerability 

The vulnerability impacts specific KMW CCTV models, including KM-IP521 running firmware IPCAM_V4.04.91.230307 and KM-IP421 with firmware IPCAM_V4.04.53.210416.

These devices are deployed globally across multiple critical infrastructure sectors, including commercial facilities, government institutions, financial services, transportation systems, and manufacturing environments.

Given their widespread usage, exploitation could have far-reaching consequences, including surveillance bypass, espionage, and operational disruption.

Although there are currently no confirmed reports of active exploitation in the wild, the vulnerability’s severity makes it a high-priority target for threat actors, especially those focusing on IoT and industrial control system weaknesses.

From a technical perspective, the flaw allows attackers to bypass authentication controls by sending crafted requests that trigger password changes without verifying the requester’s identity.

For example, an attacker on the same network, or one who exposes devices to the internet, could issue unauthorized commands to reset credentials and gain administrative access within seconds.

Security researcher Souvik Kandar has been credited with discovering and reporting the flaw to CISA. This type of attack does not require advanced skills, making it particularly dangerous in poorly secured environments.

According to a recent CISA advisory (ICSA-26-148-06), organizations should reduce exposure by keeping devices off the public internet and behind firewalls or isolated networks.

Remote access should be enabled only through secure channels, such as updated VPNs, and organizations should ensure that all connected systems follow strict security practices.

Regular risk assessments and impact analysis are also advised before implementing changes.

Additionally, organizations are encouraged to monitor for suspicious activity, follow incident response procedures, and report anomalies to relevant authorities for correlation and threat tracking.

Implementing defense-in-depth strategies and adhering to ICS cybersecurity guidelines can significantly reduce the risk of exploitation.

As surveillance infrastructure increasingly becomes a target for cyberattacks, this vulnerability highlights the urgent need for stronger security controls in IoT-based camera systems.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVECybersecurityExploitSecurityThreatVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Researcher Claims Microsoft MSRC Dismissed Dependency Confusion

Next Post

Anthropic Expands Claude Mythos AI Preview to 1 Project Glasswing

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Malicious Packages Steal Cloud Keys, Wallets & Hackers Credentials
June 2, 2026
Mustang Panda Deploys PlugX RAT via LNK Through Multi-Stage
June 2, 2026
SolyxImmortal Python Malware Steals Browser Data Passwords Cookies
June 2, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us