CVE-2026-5386
9.1 CRITICALThe affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset
Published: 2026-05-29 · Last updated: 2026-06-01
Severity and scoring
- CVSS
- 9.1 CRITICAL
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- CWE
- CWE-620
Description
The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password to a known value without authentication, granting full access to the camera feeds and settings.
Source: NVD
References
Related CVEs
Same CWE
- CVE-2026-8327 — Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass (4.3 MEDIUM)