Description

A critical security vulnerability affecting KMW CCTV cameras has been disclosed under CVE-2026-5386. The flaw allows attackers to bypass authentication controls and change device credentials without proper verification, potentially granting full access to surveillance systems. The vulnerability received a CVSS v3 score of 9.1, reflecting its high severity and the significant risks it poses to organizations that depend on CCTV infrastructure for security monitoring. The vulnerability originates from an unverified password change mechanism within affected KMW CCTV devices. Due to insufficient validation during credential modification operations, an attacker can alter passwords without successfully authenticating to the device. Once access is obtained, threat actors may gain administrative control over the camera, view live video streams, and modify system configurations. According to the advisory, the issue impacts KM-IP521 devices running firmware IPCAM_V4.04.91.230307 and KM-IP421 devices running IPCAM_V4.04.53.210416. Because these products are deployed across critical infrastructure sectors, exploitation could facilitate unauthorized surveillance, intelligence gathering, operational disruption, or preparation for broader attacks against enterprise environments. Although no active exploitation has been reported at the time of disclosure, the simplicity and impact of the flaw make it an attractive target for cybercriminals and nation-state actors alike. The vulnerability was reported to CISA by security researcher Souvik Kandar.