Vulnerability Description
An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials enabling direct unauthorized video stream access.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xiongmaitech | Xm530V200 X6-Weq 8M Firmware | 5.00.r02.000807d8.10010.346624.s.onvif_21.06 |
| Xiongmaitech | Xm530V200 X6-Weq 8M | - |
Related Weaknesses (CWE)
References
- http://hangzhou.comPermissions Required
- http://ip.comNot Applicable
- https://luismirandaacebedo.github.io/CVE-2025-65857/ExploitMitigationThird Party Advisory
- https://www.xiongmaitech.com/en/index.php/service/notice_info/51/4
FAQ
What is CVE-2025-65857?
CVE-2025-65857 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials enabling direct unau...
How severe is CVE-2025-65857?
CVE-2025-65857 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-65857?
Check the references section above for vendor advisories and patch information. Affected products include: Xiongmaitech Xm530V200 X6-Weq 8M Firmware, Xiongmaitech Xm530V200 X6-Weq 8M.