CVE-2025-65857

HIGH

Xiongmai XM530 IP cameras - Info Disclosure

Title source: llm

Description

An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials enabling direct unauthorized video stream access.

Exploits (1)

nomisec WRITEUP
by LuisMirandaAcebedo · poc
https://github.com/LuisMirandaAcebedo/CVE-2025-65857

Scores

CVSS v3 7.5
EPSS 0.0007
EPSS Percentile 21.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-359
Status published
Products (1)
xiongmaitech/xm530v200_x6-weq_8m_firmware 5.00.r02.000807d8.10010.346624.s.onvif_21.06
Published Dec 22, 2025
Tracked Since Feb 18, 2026