CVE-2026-56414

HIGH

H.VIEW HV-500S6 IP Camera Unrestricted Upload of File with Dangerous Type

Title source: cna
STIX 2.1

Description

A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arbitrary file content to fixed, persistent filesystem locations without validating file type, structure, or size. This design omission enables the placement of unexpected or malformed data in locations intended for trusted certificate material, which could affect system integrity or behavior even after reboot.

Scores

CVSS v3 7.2
EPSS 0.0040
EPSS Percentile 32.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
H.VIEW/HV-500S6 IP Camera IPCAM_V4.06.88.251229
Published Jun 26, 2026
Tracked Since Jun 27, 2026