EIP-2026-100892
PRE-CVESIEMENS IP-Camera CVMS2025-IR / CCMS2025 - Credentials Disclosure
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-100892. PoCs published by Yakir Wizman.
AI-analyzed exploit summary This exploit discloses unauthenticated remote credentials for Siemens IP-Cameras by sending a simple HTTP GET request to a specific CGI endpoint, which returns hardcoded admin credentials in JavaScript variables.
Description
SIEMENS IP-Camera CVMS2025-IR / CCMS2025 - Credentials Disclosure
Exploits (1)
exploitdb
WORKING POC
by Yakir Wizman · textwebappscgi
https://www.exploit-db.com/exploits/40254
This exploit discloses unauthenticated remote credentials for Siemens IP-Cameras by sending a simple HTTP GET request to a specific CGI endpoint, which returns hardcoded admin credentials in JavaScript variables.
Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target:
SIEMENS IP-Camera (CVMS2025-IR, CCMS2025) versions x.2.2.1798, CxMS2025_V2458_SP1, x.2.2.1235
No auth needed
Prerequisites:
Network access to the target camera's web interface
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026