KMW CCTV Cameras CVE-2026-5386 — Unauthenticated Remote Administrator Password Reset Enables Full Camera Takeover (CWE-620, CVSS 9.1) — Threadlinqs Intelligence
As of 2026-06-02, KMW CCTV Cameras CVE-2026-5386 — Unauthenticated Remote Administrator Password Reset Enables Full Camera Takeover (CWE-620, CVSS 9.1) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 13 indicators of compromise.
Threat ID: TL-2026-0661 · Severity: CRITICAL · CVSS: 9.1 · Status: ACTIVE · Category: VULNERABILITY
CVE-2026-5386 is a critical unverified-password-change weakness (CWE-620, CVSS v3.1 9.1) in KMW IP CCTV cameras (KM-IP521, KM-IP421) that lets an unauthenticated remote attacker reset the
CVE-2026-5386 is a critical authentication-bypass vulnerability affecting KMW network CCTV security cameras, specifically the KM-IP521 (firmware IPCAM_V4.04.91.230307) and KM-IP421 (firmware IPCAM_V4.04.53.210416). The root cause is CWE-620 (Unverified Password Change): the camera's web/management interface exposes a credential-change operation that does not validate the identity of the requester. An attacker who can reach the device over the network can issue a crafted request that resets the administrator password to a known/attacker-chosen value without supplying any prior credentials, completing full account takeover in seconds.
Because the flaw requires no authentication (PR:N), no user interaction (UI:N), low attack complexity (AC:L), and is reachable over the network (AV:N), CISA assigned CVSS v3.1 base score 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) and CVSS v4.0 vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N. Confidentiality and integrity impact are HIGH; availability impact is rated NONE in the base metrics, although in practice an attacker who has reset the admin password can lock out legitimate operators (account access removal) and stop recording/streaming services, producing an operational-availability effect not captured by the base score.
Exploit chain: (1) Reconnaissance — an attacker discovers internet-exposed KMW cameras (e.g., via mass scanning for the device web interface, ONVIF, RTSP, or the KMW P2P cloud connection), or is positioned on the same LAN/segment as the device. (2) Initial access / credential access — the attacker sends a crafted HTTP request to the unprotected password-change endpoint, which the firmware applies without verifying the caller's identity, setting the admin credential to a known value. (3) Persistence — by controlling the admin account (account manipulation), the attacker retains durable access until an operator notices and reflashes/resets the device. (4) Collection — the attacker authenticates with the new password and accesses live and recorded video feeds (video capture). (5) Impact — the attacker can alter device configuration (data manipulation), disable surveillance/recording (service stop / impair defenses), and remove legitimate operator access (account access removal), enabling surveillance bypass, espionage, and operational disruption in physical-security deployments.
KMW (headquartered in Romania) has released a firmware update addressing the vulnerability, distributed at https://main.kmw.ro/pub/Firmware/521_421.zip. Note that updating the KM-IP421 invalidates its cloud authorization, requiring users to contact KMW support to re-authorize the P2P connection. The vulnerability was reported to CISA by security researcher Souvik Kandar. The CISA SSVC decision point recorded E:N (no known public exploitation) as of 2026-05-27. No public proof-of-concept exploit code has been published, but the triviality of the flaw makes it a high-priority target. These cameras are deployed worldwide across commercial facilities, government services and facilities, critical manufacturing, financial services, and transportation systems, making exposed unpatched devices an attractive foothold for physical-surveillance compromise.
Target sectors: commercial facilities, government, critical manufacturing, financial services, transportation
Target regions: Worldwide
Detections & IOCs
As of 2026-08-10, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 13 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-5386, T1595, T1592, T1190, T1133, T1556, T1098, T1125, T1531, T1565, T1489