CVE-2025-65857

An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials enabling direct unauthorized video stream access.
References
Link Resource
http://hangzhou.com Permissions Required
http://ip.com Not Applicable
https://luismirandaacebedo.github.io/CVE-2025-65857/ Exploit Third Party Advisory Mitigation
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:xiongmaitech:xm530v200_x6-weq_8m_firmware:5.00.r02.000807d8.10010.346624.s.onvif_21.06:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:xm530v200_x6-weq_8m:-:*:*:*:*:*:*:*

History

05 Jan 2026, 18:20

Type Values Removed Values Added
References () http://hangzhou.com - () http://hangzhou.com - Permissions Required
References () http://ip.com - () http://ip.com - Not Applicable
References () https://luismirandaacebedo.github.io/CVE-2025-65857/ - () https://luismirandaacebedo.github.io/CVE-2025-65857/ - Exploit, Third Party Advisory, Mitigation
First Time Xiongmaitech xm530v200 X6-weq 8m Firmware
Xiongmaitech
Xiongmaitech xm530v200 X6-weq 8m
CPE cpe:2.3:o:xiongmaitech:xm530v200_x6-weq_8m_firmware:5.00.r02.000807d8.10010.346624.s.onvif_21.06:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:xm530v200_x6-weq_8m:-:*:*:*:*:*:*:*

22 Dec 2025, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-22 22:16

Updated : 2026-01-05 18:20


NVD link : CVE-2025-65857

Mitre link : CVE-2025-65857

CVE.ORG link : CVE-2025-65857


JSON object : View

Products Affected

xiongmaitech

  • xm530v200_x6-weq_8m_firmware
  • xm530v200_x6-weq_8m
CWE
CWE-359

Exposure of Private Personal Information to an Unauthorized Actor