CVE-2025-65856

Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video streams. The ONVIF implementation fails to enforce authentication on 31 critical endpoints, enabling direct unauthorized video stream access.
References
Link Resource
http://hangzhou.com Not Applicable
http://ip.com Not Applicable
https://luismirandaacebedo.github.io/CVE-2025-65856/ Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:xiongmaitech:xm530v200_x6-weq_8m_firmware:5.00.r02.000807d8.10010.346624.s.onvif_21.06:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:xm530v200_x6-weq_8m:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-22 22:16

Updated : 2026-01-05 18:28


NVD link : CVE-2025-65856

Mitre link : CVE-2025-65856

CVE.ORG link : CVE-2025-65856


JSON object : View

Products Affected

xiongmaitech

  • xm530v200_x6-weq_8m
  • xm530v200_x6-weq_8m_firmware
CWE
CWE-306

Missing Authentication for Critical Function