Exploitation Summary
EIP tracks 1 public exploit for CVE-2025-65857. PoCs published by LuisMirandaAcebedo.
AI-analyzed exploit summary This repository documents CVE-2025-65857, a critical vulnerability in Xiongmai XM530 IP cameras where hardcoded RTSP credentials are exposed via the ONVIF GetStreamUri endpoint, allowing unauthenticated access to live video streams.
Description
An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials enabling direct unauthorized video stream access.
Exploits (1)
This repository documents CVE-2025-65857, a critical vulnerability in Xiongmai XM530 IP cameras where hardcoded RTSP credentials are exposed via the ONVIF GetStreamUri endpoint, allowing unauthenticated access to live video streams.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N