← All CVEs

CVE-2025-65856

critical · 9.8

Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video streams. The ONVIF implementation fails to enforce authentication on 31 critical endpoints, enabling direct unauthorized video stream access.

9.8
CVSS
0.7%
EPSS (exploit prob.)
53rd
EPSS percentile
2025-12-22
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-306

Affected products

VendorProductAffected versions
xiongmaitechxm530v200_x6-weq_8m_firmware5.00.r02.000807d8.10010.346624.s.onvif_21.06
xiongmaitechxm530v200_x6-weq_8mall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-65856