EIP-2026-100892

PRE-CVE

SIEMENS IP-Camera CVMS2025-IR / CCMS2025 - Credentials Disclosure

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-100892. PoCs published by Yakir Wizman.

AI-analyzed exploit summary This exploit discloses unauthenticated remote credentials for Siemens IP-Cameras by sending a simple HTTP GET request to a specific CGI endpoint, which returns hardcoded admin credentials in JavaScript variables.

Description

SIEMENS IP-Camera CVMS2025-IR / CCMS2025 - Credentials Disclosure

Exploits (1)

exploitdb WORKING POC
by Yakir Wizman · textwebappscgi
https://www.exploit-db.com/exploits/40254

This exploit discloses unauthenticated remote credentials for Siemens IP-Cameras by sending a simple HTTP GET request to a specific CGI endpoint, which returns hardcoded admin credentials in JavaScript variables.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: SIEMENS IP-Camera (CVMS2025-IR, CCMS2025) versions x.2.2.1798, CxMS2025_V2458_SP1, x.2.2.1235
No auth needed
Prerequisites: Network access to the target camera's web interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026