Project Subscriptions
No data.
No advisories yet.
Solution
KMW has issued a firmware update to address this vulnerability. The firmware update can be found at: https://main.kmw.ro/pub/Firmware/521_421.zip KM-IP421 - will lose the cloud authorization after this update so users will need to contact customer support to re-authorize the P2P connection. If there are any issues customers are encouraged to contact KMW directly.
Workaround
KMW recommends connecting surveillance equipment on a separate network, allow only specific devices access to the internet, check for firmware updates regularly, and use cloud connections responsibly.
Fri, 29 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password to a known value without authentication, granting full access to the camera feeds and settings. | |
| Title | KMW CCTV Security Cameras Unverified Password Change | |
| Weaknesses | CWE-620 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-05-29T19:30:48.817Z
Reserved: 2026-04-01T20:46:32.932Z
Link: CVE-2026-5386
Updated: 2026-05-29T19:30:44.624Z
Status : Received
Published: 2026-05-29T18:17:12.867
Modified: 2026-05-29T18:17:12.867
Link: CVE-2026-5386
No data.
OpenCVE Enrichment
Updated: 2026-05-29T19:00:06Z