CISA warns of vulnerability affecting surveillance cameras deployed across critical infrastructure worldwide.
- CVE-2026-5386 enables remote password reset without authentication on KMW IP cameras
- Vulnerability grants full access to camera feeds and administrative settings
- Firmware update available for affected KM-IP521 and KM-IP421 models
CISA has issued an advisory warning of a critical vulnerability in KMW CCTV security cameras that allows attackers to reset administrator passwords without authentication. The flaw, tracked as CVE-2026-5386, carries a CVSS score of 9.1 and affects cameras deployed across critical infrastructure sectors worldwide.
The vulnerability enables remote attackers to reset the administrator password to a known value, providing complete access to camera feeds and device settings. Two camera models are confirmed vulnerable: the KM-IP521 running firmware IPCAM_V4.04.91.230307 and the KM-IP421 running firmware IPCAM_V4.04.53.210416.
According to CISA’s advisory, the affected cameras are deployed across commercial facilities, government services, critical manufacturing, financial services and transportation systems. The Romanian manufacturer KMW has distributed these devices globally.
Security researcher Souvik Kandar discovered and reported the vulnerability, which falls under CWE-620 (Unverified Password Change). The flaw requires no user interaction and can be exploited remotely over the network without prior authentication.
KMW has released a firmware update to address the vulnerability. The company advises that the KM-IP421 model will lose cloud authorisation after the update, requiring users to contact customer support to re-establish P2P connections. The firmware update is available from KMW’s website.
Beyond patching, KMW recommends connecting surveillance equipment on isolated networks, restricting internet access to specific devices, checking for firmware updates regularly, and using cloud connections responsibly.
Why It Matters
This vulnerability represents a significant risk to organisations using these cameras for physical security monitoring. Unauthorised access to surveillance feeds can compromise security operations, enable reconnaissance for physical attacks, and expose sensitive activities. The global deployment across critical infrastructure sectors amplifies the potential impact.
For CISOs, this incident highlights the security risks of connected surveillance systems and the need for robust network segmentation around physical security infrastructure. Board reporting should emphasise how compromised cameras could undermine overall security posture and regulatory compliance requirements.
What To Do Now
- Inventory KMW camera deployments and verify firmware versions against CISA’s advisory
- Apply the firmware update immediately for affected models following KMW’s remediation guidance
- Implement network segmentation to isolate surveillance systems from corporate networks as recommended by KMW’s mitigation advice
