Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video streams. The ONVIF implementation fails to enforce authentication on 31 critical endpoints, enabling direct unauthorized video stream access.
References
| Link | Resource |
|---|---|
| http://hangzhou.com | Not Applicable |
| http://ip.com | Not Applicable |
| https://luismirandaacebedo.github.io/CVE-2025-65856/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2025-12-22 22:16
Updated : 2026-01-05 18:28
NVD link : CVE-2025-65856
Mitre link : CVE-2025-65856
CVE.ORG link : CVE-2025-65856
JSON object : View
Products Affected
xiongmaitech
- xm530v200_x6-weq_8m
- xm530v200_x6-weq_8m_firmware
CWE
CWE-306
Missing Authentication for Critical Function
