CVE-2025-65856

Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video streams. The ONVIF implementation fails to enforce authentication on 31 critical endpoints, enabling direct unauthorized video stream access.
References
Link Resource
http://hangzhou.com Not Applicable
http://ip.com Not Applicable
https://luismirandaacebedo.github.io/CVE-2025-65856/ Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:xiongmaitech:xm530v200_x6-weq_8m_firmware:5.00.r02.000807d8.10010.346624.s.onvif_21.06:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:xm530v200_x6-weq_8m:-:*:*:*:*:*:*:*

History

05 Jan 2026, 18:28

Type Values Removed Values Added
References () http://hangzhou.com - () http://hangzhou.com - Not Applicable
References () http://ip.com - () http://ip.com - Not Applicable
References () https://luismirandaacebedo.github.io/CVE-2025-65856/ - () https://luismirandaacebedo.github.io/CVE-2025-65856/ - Exploit, Third Party Advisory
First Time Xiongmaitech xm530v200 X6-weq 8m Firmware
Xiongmaitech
Xiongmaitech xm530v200 X6-weq 8m
CPE cpe:2.3:o:xiongmaitech:xm530v200_x6-weq_8m_firmware:5.00.r02.000807d8.10010.346624.s.onvif_21.06:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:xm530v200_x6-weq_8m:-:*:*:*:*:*:*:*

22 Dec 2025, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-22 22:16

Updated : 2026-01-05 18:28


NVD link : CVE-2025-65856

Mitre link : CVE-2025-65856

CVE.ORG link : CVE-2025-65856


JSON object : View

Products Affected

xiongmaitech

  • xm530v200_x6-weq_8m_firmware
  • xm530v200_x6-weq_8m
CWE
CWE-306

Missing Authentication for Critical Function