Threat reportVulnerabilityTL-2026-0661

KMW CCTV Cameras CVE-2026-5386 — Unauthenticated Remote Administrator Password Reset Enables Full Camera Takeover (CWE-620, CVSS 9.1)

criticalACTIVE

KMW CCTV Cameras CVE-2026-5386 (TL-2026-0661), also tracked as ICSA-26-148-06, is a critical-severity software vulnerability scored CVSS 9.1, first published 2026-06-02. It has no confirmed attribution, affects KMW KM-IP521, references 1 CVE (CVE-2026-5386), maps to 11 MITRE ATT&CK techniques (T1098, T1125, T1133), and is covered by 9 detection rules and 13 indicators of compromise.

CVSS
9.1/10Critical
CVEs
1Referenced vulnerabilities
Techniques
11MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
13Indicators of compromise

Key facts for TL-2026-0661

Threat ID
TL-2026-0661
Also known as
ICSA-26-148-06
Severity
CRITICAL
CVSS
9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
commercial facilities, government, critical manufacturing, financial services, transportation
Target regions
Worldwide
Detection rules
9
Indicators of compromise
13

How KMW CCTV Cameras CVE-2026-5386 works

CVE-2026-5386 is a critical unverified-password-change weakness (CWE-620, CVSS v3.1 9.1) in KMW IP CCTV cameras (KM-IP521, KM-IP421) that lets an unauthenticated remote attacker reset the administrator password to a known value via a crafted request. Successful exploitation grants full administrative control — live video feed access, configuration tampering, and surveillance disablement. CISA published ICS advisory ICSA-26-148-06 on 2026-05-28; no in-the-wild exploitation has been reported as of 2026-06-02.

CVE-2026-5386 is a critical authentication-bypass vulnerability affecting KMW network CCTV security cameras, specifically the KM-IP521 (firmware IPCAM_V4.04.91.230307) and KM-IP421 (firmware IPCAM_V4.04.53.210416). The root cause is CWE-620 (Unverified Password Change): the camera's web/management interface exposes a credential-change operation that does not validate the identity of the requester. An attacker who can reach the device over the network can issue a crafted request that resets the administrator password to a known/attacker-chosen value without supplying any prior credentials, completing full account takeover in seconds.

Because the flaw requires no authentication (PR:N), no user interaction (UI:N), low attack complexity (AC:L), and is reachable over the network (AV:N), CISA assigned CVSS v3.1 base score 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) and CVSS v4.0 vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N. Confidentiality and integrity impact are HIGH; availability impact is rated NONE in the base metrics, although in practice an attacker who has reset the admin password can lock out legitimate operators (account access removal) and stop recording/streaming services, producing an operational-availability effect not captured by the base score.

Exploit chain: (1) Reconnaissance — an attacker discovers internet-exposed KMW cameras (e.g., via mass scanning for the device web interface, ONVIF, RTSP, or the KMW P2P cloud connection), or is positioned on the same LAN/segment as the device. (2) Initial access / credential access — the attacker sends a crafted HTTP request to the unprotected password-change endpoint, which the firmware applies without verifying the caller's identity, setting the admin credential to a known value. (3) Persistence — by controlling the admin account (account manipulation), the attacker retains durable access until an operator notices and reflashes/resets the device. (4) Collection — the attacker authenticates with the new password and accesses live and recorded video feeds (video capture). (5) Impact — the attacker can alter device configuration (data manipulation), disable surveillance/recording (service stop / impair defenses), and remove legitimate operator access (account access removal), enabling surveillance bypass, espionage, and operational disruption in physical-security deployments.

KMW (headquartered in Romania) has released a firmware update addressing the vulnerability, distributed at https://main.kmw.ro/pub/Firmware/521_421.zip. Note that updating the KM-IP421 invalidates its cloud authorization, requiring users to contact KMW support to re-authorize the P2P connection. The vulnerability was reported to CISA by security researcher Souvik Kandar. The CISA SSVC decision point recorded E:N (no known public exploitation) as of 2026-05-27. No public proof-of-concept exploit code has been published, but the triviality of the flaw makes it a high-priority target. These cameras are deployed worldwide across commercial facilities, government services and facilities, critical manufacturing, financial services, and transportation systems, making exposed unpatched devices an attractive foothold for physical-surveillance compromise.

MITRE ATT&CK techniques used in TL-2026-0661

Persistence

T1098 Account Manipulation

Collection

T1125 Video Capture

Initial Access

T1133 External Remote Services; T1190 Exploit Public-Facing Application

Impact

T1489 Service Stop; T1531 Account Access Removal; T1565 Data Manipulation

Credential Access

T1556 Modify Authentication Process

Reconnaissance

T1592 Gather Victim Host Information; T1595 Active Scanning

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in KMW CCTV Cameras CVE-2026-5386

  • KMW — KM-IP521
    Vulnerable versions: IPCAM_V4.04.91.230307
    Fixed in: Firmware update at main.kmw.ro/pub/Firmware/521_421.zip
  • KMW — KM-IP421
    Vulnerable versions: IPCAM_V4.04.53.210416
    Fixed in: Firmware update at main.kmw.ro/pub/Firmware/521_421.zip (cloud re-authorization required)

Remediation for KMW CCTV Cameras CVE-2026-5386

Patches

  • Apply KMW firmware update for KM-IP521 and KM-IP421 from https://main.kmw.ro/pub/Firmware/521_421.zip
  • After updating KM-IP421, contact KMW customer support to re-authorize the P2P cloud connection (cloud authorization is lost during update)

Immediate actions

  • Remove KMW KM-IP521 and KM-IP421 cameras from direct internet exposure; place behind a firewall and on an isolated/segmented surveillance VLAN
  • Audit perimeter and device-facing firewall rules for inbound access to camera web interface, ONVIF, RTSP, and P2P/cloud ports; block where not required
  • Verify current admin credentials on all KMW cameras and watch for unexpected admin password changes or lockouts indicating prior compromise

Workarounds

  • Isolate cameras on a dedicated network segment that permits only specific authorized management hosts to reach the device
  • Disable the P2P/cloud connection feature where not operationally required to reduce remote attack surface
  • Restrict device internet access to only required destinations

Longer-term hardening

  • Place all surveillance/control-system devices behind firewalls, isolated from business networks (CISA recommended practice)
  • Require secure remote access (up-to-date VPN) for any external management; never expose camera management directly to the internet
  • Establish a firmware patch-management cadence for IoT/edge surveillance devices and inventory all KMW deployments
  • Deploy network monitoring to alert on unauthenticated credential-change requests and anomalous access to camera management endpoints

CVEs associated with KMW CCTV Cameras CVE-2026-5386

CVE-2026-5386

Weaknesses (CWE) in KMW CCTV Cameras CVE-2026-5386

CWE-620

Timeline of KMW CCTV Cameras CVE-2026-5386

  • Vulnerability reported to CISA by security researcher Souvik Kandar; SSVC decision recorded E:N (no known public exploitation).
  • KMW released a firmware update for KM-IP521 and KM-IP421 at main.kmw.ro/pub/Firmware/521_421.zip; KM-IP421 requires P2P cloud re-authorization after update.
  • CISA published ICS advisory ICSA-26-148-06 (TLP:WHITE) detailing CVE-2026-5386 in KMW KM-IP521 and KM-IP421 cameras.
  • CVE-2026-5386 published in NVD (source ics-cert@hq.dhs.gov) with CVSS v3.1 base score 9.1, CWE-620.
  • NVD record last modified; vulnStatus 'Awaiting Analysis'.
  • Threadlinqs Intelligence documented threat TL-2026-0661 with full MITRE mapping, IOCs, and detection coverage.
  • Cyber Security News published public reporting on the KMW CCTV vulnerability; no confirmed in-the-wild exploitation as of this date.

Sources cited for KMW CCTV Cameras CVE-2026-5386

Detection coverage for TL-2026-0661

As of 2026-06-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0661 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
13 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats