QSearchQSearch

CVE-2026-5386

9.1 CRITICAL

The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset

Published: 2026-05-29 · Last updated: 2026-06-01

Severity and scoring

CVSS
9.1 CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE
CWE-620

Description

The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password to a known value without authentication, granting full access to the camera feeds and settings.

Source: NVD

References

Related CVEs

Same CWE

  • CVE-2026-8327 Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass (4.3 MEDIUM)