Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video streams. The ONVIF implementation fails to enforce authentication on 31 critical endpoints, enabling direct unauthorized video stream access.
References
| Link | Resource |
|---|---|
| http://hangzhou.com | Not Applicable |
| http://ip.com | Not Applicable |
| https://luismirandaacebedo.github.io/CVE-2025-65856/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
05 Jan 2026, 18:28
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://hangzhou.com - Not Applicable | |
| References | () http://ip.com - Not Applicable | |
| References | () https://luismirandaacebedo.github.io/CVE-2025-65856/ - Exploit, Third Party Advisory | |
| First Time |
Xiongmaitech xm530v200 X6-weq 8m Firmware
Xiongmaitech Xiongmaitech xm530v200 X6-weq 8m |
|
| CPE | cpe:2.3:o:xiongmaitech:xm530v200_x6-weq_8m_firmware:5.00.r02.000807d8.10010.346624.s.onvif_21.06:*:*:*:*:*:*:* cpe:2.3:h:xiongmaitech:xm530v200_x6-weq_8m:-:*:*:*:*:*:*:* |
22 Dec 2025, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-22 22:16
Updated : 2026-01-05 18:28
NVD link : CVE-2025-65856
Mitre link : CVE-2025-65856
CVE.ORG link : CVE-2025-65856
JSON object : View
Products Affected
xiongmaitech
- xm530v200_x6-weq_8m_firmware
- xm530v200_x6-weq_8m
CWE
CWE-306
Missing Authentication for Critical Function
