HIGH · 7.5

CVE-2025-65857

An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials enabling direct unau...

Vulnerability Description

An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials enabling direct unauthorized video stream access.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
XiongmaitechXm530V200 X6-Weq 8M Firmware5.00.r02.000807d8.10010.346624.s.onvif_21.06
XiongmaitechXm530V200 X6-Weq 8M-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-65857?

CVE-2025-65857 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials enabling direct unau...

How severe is CVE-2025-65857?

CVE-2025-65857 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2025-65857?

Check the references section above for vendor advisories and patch information. Affected products include: Xiongmaitech Xm530V200 X6-Weq 8M Firmware, Xiongmaitech Xm530V200 X6-Weq 8M.