Critical KMW CCTV Vulnerability Exposes Camera Feeds
Key Takeaways A critical vulnerability (CVE-2026-5386) has been identified in KMW CCTV cameras. The flaw allows remote attackers to change device passwords without authentication, granting full...
Key Takeaways
- A critical vulnerability (CVE-2026-5386) has been identified in KMW CCTV cameras.
- The flaw allows remote attackers to change device passwords without authentication, granting full control over camera feeds and settings.
- Affected models include KM-IP521 (firmware IPCAM_V4.04.91.230307) and KM-IP421 (firmware IPCAM_V4.04.53.210416).
- With a CVSS v3 score of 9.1, the vulnerability poses a severe risk to organizations across various critical infrastructure sectors.
- No patch is currently available, emphasizing the need for robust mitigation strategies.
KMW CCTV security cameras are exposed to a critical vulnerability that could allow unauthorized individuals to gain complete access to live video streams and device configurations. This severe flaw enables attackers to remotely alter authentication credentials without proper validation, effectively hijacking surveillance operations.
Table Of Content
Designated as CVE-2026-5386, the security weakness carries a CVSS v3 score of 9.1, underscoring its significant potential impact on entities reliant on these monitoring systems.
Understanding the KMW CCTV Vulnerability
The core of the issue lies in an “unverified password change” mechanism within the affected KMW devices. This defect permits remote threat actors to reset passwords without the system verifying the user’s identity. Once exploited, malicious actors can seize control of the camera, access real-time video feeds, modify settings, or even disable surveillance functions entirely.
Such unauthorized access presents substantial security hazards, particularly in sensitive environments where CCTV systems are crucial for safety and monitoring. The vulnerability impacts specific KMW CCTV models: the KM-IP521, running firmware IPCAM_V4.04.91.230307, and the KM-IP421, with firmware IPCAM_V4.04.53.210416.
These devices are widely deployed across various critical infrastructure sectors globally, including commercial enterprises, governmental bodies, financial institutions, transportation networks, and manufacturing facilities. Given their pervasive use, successful exploitation could lead to widespread consequences such as surveillance circumvention, espionage, and operational interruptions.
While there are no confirmed reports of this vulnerability being actively exploited in the wild, its high severity makes it an attractive target for threat actors, especially those who specialize in Internet of Things (IoT) and industrial control system (ICS) weaknesses.
Technically, the flaw allows attackers to bypass standard authentication by sending specially crafted requests that trigger a password change without validating the requester’s identity. For instance, an attacker on the same network or one targeting devices exposed to the internet could issue unauthorized commands to reset credentials and obtain administrative access swiftly.
Security researcher Souvik Kandar is credited with discovering and reporting this flaw to CISA. The relatively low skill requirement for this type of attack makes it particularly dangerous for poorly secured environments.
What You Should Do
- Restrict Network Exposure: Keep KMW CCTV devices off the public internet. Ensure they are isolated behind firewalls or on dedicated, segmented networks.
- Secure Remote Access: If remote access is essential, enable it only through secure channels, such as up-to-date Virtual Private Networks (VPNs).
- Implement Defense-in-Depth: Apply multiple layers of security controls, following established ICS cybersecurity guidelines.
- Monitor for Anomalies: Continuously monitor network traffic and device logs for any suspicious activities or unauthorized access attempts.
- Conduct Risk Assessments: Perform regular risk assessments and impact analyses before implementing any network or system changes.
- Report Incidents: Follow organizational incident response procedures and report any detected anomalies or potential exploitation attempts to relevant authorities for threat correlation and tracking, as advised by a recent CISA advisory (ICSA-26-148-06).
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.