CVE-2026-55975Disclosure

MEDIUMCVSS 8.6 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability exists in H.View IP cameras that could allow an authenticated user to supply unsanitized XML fields to the device's certificate generation interface, which are incorporated into a backend certificate creation command without proper input validation. This may allow for command execution with elevated privileges during certificate generation.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-06-26); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-06-26: 1Mentions · 2026-06-27: 1Mentions · 2026-06-28: 1Mentions · 2026-06-29: 1Active Exploitation · 2026-06-27: 1Patch / Workaround · 2026-06-28: 1Patch / Workaround · 2026-06-29: 1Technical Details · 2026-06-26: 1Technical Details · 2026-06-27: 1Technical Details · 2026-06-28: 1Technical Details · 2026-06-29: 106-2606-2706-2806-29
Signal classification3 categories
Disclosure
250.0%
Active Exploitation
125.0%
Patch
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-261
Disclosure1
2026-06-271
Active Exploitation1
2026-06-281
Patch1
2026-06-291
Disclosure1
Full discourse4 posts
  • ちゃちゃ@doudemo_nandemo
    Disclosure

    CVE-2026-55975 / CVE-2026-56414 中国製IPカメラ H.VIEW HV-500S6 のOSコマンドインジェクションと任意ファイルアップロードを CISA に報告し、ICS Advisoryとして公開されました!!!! https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-05 https://t.co/VpUZPZDXVr

    Post summary

    Two CVEs (CVE-2026-55975 and CVE-2026-56414) have been reported to CISA as OS command injection and arbitrary file upload vulnerabilities in the H.VIEW HV-500S6 IP camera; the report is an official advisory with no PoC, exploit code, or patch information provided.

    0622835.9K
    1.2K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    #CVE-2026-55975 - #Command Injection in H.View IP #cameras. Authenticated users can exploit unsanitized XML fields for elevated command execution. #CVSS 7.2. No patch available. Isolate affected devices immediately. #CVEAlert #infosec #HView #cybersecurity More:

    Post summary

    The tweet announces CVE-2026-55975, a command injection vulnerability in H.View IP cameras that requires authentication and carries a CVSS score of 7.2. No patch is available; users are advised to isolate affected devices.

    1000084
    965 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH SEVERITY: CVE-2026-55975 H[.]View IP cameras vulnerable to command injection via XML fields in certificate generation (CVSS 7.2). Authenticated attackers can execute commands with elevated privileges. Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/4MZAQrJAk5

    Post summary

    The tweet warns of CVE‑2026‑55975 in H[.]View IP cameras, detailing a command injection flaw that allows authenticated attackers to run commands, and urges immediate patching.

    0000049
    52 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploited CVE-2026-55975 in H.VIEW HV-500S6 IP cameras, injecting commands through unsanitized XML fields during certificate generation. The vulnerability enables privilege escalation and lateral movement across connected infrastructure. Runtime segmentation helps limit blast radius in compromised IoT environments. #IoTSecurity #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/icsa-26-176-05-h-view-hv-500s6-ip-camera-vulnerabilities

    Post summary

    The analysis confirms CVE-2026-55975 was actively exploited in H.VIEW HV-500S6 IP cameras, enabling privilege escalation and lateral movement, with no patch or PoC disclosed.

    0000058
    1.9K followersView on X

Explore more