CVE-2025-65856
Unknown
Unknown - Not Provided
Authentication Bypass in Xiongmai XM530 Cameras Enables Unauthorized Video Access
Publication date: 2025-12-22
Last updated on: 2025-12-22
Assigner: MITRE
Description
Description
Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video streams. The ONVIF implementation fails to enforce authentication on 31 critical endpoints, enabling direct unauthorized video stream access.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| xiongmai | xm530 | From 5.00.R02.000807D8.10010.346624.S.ONVIF (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |