CVE-2025-65857

An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials enabling direct unauthorized video stream access.
References
Link Resource
http://hangzhou.com Permissions Required
http://ip.com Not Applicable
https://luismirandaacebedo.github.io/CVE-2025-65857/ Exploit Third Party Advisory Mitigation
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:xiongmaitech:xm530v200_x6-weq_8m_firmware:5.00.r02.000807d8.10010.346624.s.onvif_21.06:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:xm530v200_x6-weq_8m:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-22 22:16

Updated : 2026-01-05 18:20


NVD link : CVE-2025-65857

Mitre link : CVE-2025-65857

CVE.ORG link : CVE-2025-65857


JSON object : View

Products Affected

xiongmaitech

  • xm530v200_x6-weq_8m
  • xm530v200_x6-weq_8m_firmware
CWE
CWE-359

Exposure of Private Personal Information to an Unauthorized Actor