# KMW CCTV Cameras CVE-2026-5386 — Unauthenticated Remote Administrator Password Reset Enables Full Camera Takeover (CWE-620, CVSS 9.1)

> CVE-2026-5386 is a critical unverified-password-change weakness (CWE-620, CVSS v3.1 9.1) in KMW IP CCTV cameras (KM-IP521, KM-IP421) that lets an unauthenticated remote attacker reset the administrator password to a known value via a crafted request. Successful exploitation grants full administrative control — live video feed access, configuration tampering, and surveillance disablement. CISA published ICS advisory ICSA-26-148-06 on 2026-05-28; no in-the-wild exploitation has been reported as of 2026-06-02.

- **Published:** 2026-06-02T00:00:00Z
- **Last reviewed:** 2026-06-02T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0661
- **ID:** TL-2026-0661
- **Severity:** CRITICAL (CVSS 9.1)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 13 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-5386

## Description

CVE-2026-5386 is a critical authentication-bypass vulnerability affecting KMW network CCTV security cameras, specifically the KM-IP521 (firmware IPCAM_V4.04.91.230307) and KM-IP421 (firmware IPCAM_V4.04.53.210416). The root cause is CWE-620 (Unverified Password Change): the camera's web/management interface exposes a credential-change operation that does not validate the identity of the requester. An attacker who can reach the device over the network can issue a crafted request that resets the administrator password to a known/attacker-chosen value without supplying any prior credentials, completing full account takeover in seconds.

Because the flaw requires no authentication (PR:N), no user interaction (UI:N), low attack complexity (AC:L), and is reachable over the network (AV:N), CISA assigned CVSS v3.1 base score 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) and CVSS v4.0 vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N. Confidentiality and integrity impact are HIGH; availability impact is rated NONE in the base metrics, although in practice an attacker who has reset the admin password can lock out legitimate operators (account access removal) and stop recording/streaming services, producing an operational-availability effect not captured by the base score.

Exploit chain: (1) Reconnaissance — an attacker discovers internet-exposed KMW cameras (e.g., via mass scanning for the device web interface, ONVIF, RTSP, or the KMW P2P cloud connection), or is positioned on the same LAN/segment as the device. (2) Initial access / credential access — the attacker sends a crafted HTTP request to the unprotected password-change endpoint, which the firmware applies without verifying the caller's identity, setting the admin credential to a known value. (3) Persistence — by controlling the admin account (account manipulation), the attacker retains durable access until an operator notices and reflashes/resets the device. (4) Collection — the attacker authenticates with the new password and accesses live and recorded video feeds (video capture). (5) Impact — the attacker can alter device configuration (data manipulation), disable surveillance/recording (service stop / impair defenses), and remove legitimate operator access (account access removal), enabling surveillance bypass, espionage, and operational disruption in physical-security deployments.

KMW (headquartered in Romania) has released a firmware update addressing the vulnerability, distributed at https://main.kmw.ro/pub/Firmware/521_421.zip. Note that updating the KM-IP421 invalidates its cloud authorization, requiring users to contact KMW support to re-authorize the P2P connection. The vulnerability was reported to CISA by security researcher Souvik Kandar. The CISA SSVC decision point recorded E:N (no known public exploitation) as of 2026-05-27. No public proof-of-concept exploit code has been published, but the triviality of the flaw makes it a high-priority target. These cameras are deployed worldwide across commercial facilities, government services and facilities, critical manufacturing, financial services, and transportation systems, making exposed unpatched devices an attractive foothold for physical-surveillance compromise.

## MITRE ATT&CK

- T1595 Active Scanning
- T1592 Gather Victim Host Information
- T1190 Exploit Public-Facing Application
- T1133 External Remote Services
- T1556 Modify Authentication Process
- T1098 Account Manipulation
- T1125 Video Capture
- T1531 Account Access Removal
- T1565 Data Manipulation
- T1489 Service Stop
- T1685 Disable or Modify Tools

## Sources

- [CISA ICS Advisory ICSA-26-148-06 — KMW CCTV Security Cameras](https://www.cisa.gov/news-events/ics-advisories/icsa-26-148-06)
- [CISA CSAF — icsa-26-148-06.json](https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-148-06.json)
- [NVD — CVE-2026-5386](https://nvd.nist.gov/vuln/detail/CVE-2026-5386)
- [CVE Record — CVE-2026-5386](https://www.cve.org/CVERecord?id=CVE-2026-5386)
- [CWE-620: Unverified Password Change](https://cwe.mitre.org/data/definitions/620.html)
- [Critical KMW CCTV Vulnerability Let Attackers Gain Unauthorized Access to Camera Feeds](https://cybersecuritynews.com/kmw-cctv-vulnerability/)
- [KMW Firmware Update (KM-IP521 / KM-IP421)](https://main.kmw.ro/pub/Firmware/521_421.zip)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0661
