CVE-2025-65856 Details
Description
Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video streams. The ONVIF implementation fails to enforce authentication on 31 critical endpoints, enabling direct unauthorized video stream access.
An authentication bypass vulnerability has been identified in Xiongmai XM530 IP cameras running ONVIF firmware version V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. This vulnerability allows unauthenticated remote attackers to access sensitive device information and live video streams. The issue arises because the ONVIF implementation fails to enforce authentication on 31 critical endpoints, enabling direct unauthorized access to video streams and other sensitive data.
Users are advised to isolate the cameras on a separate VLAN without internet access, block inbound connections to common ports used by the cameras, disable the ONVIF protocol if possible, and avoid exposing the cameras directly to the internet. Given the vendor's poor security history, replacement of the cameras is recommended. The vendor should implement proper WS-Security authentication on all ONVIF endpoints, follow ONVIF Core Specification security requirements, add rate limiting and brute force protection, and enable security logging and alerts. However, no patch is currently available.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://luismirandaacebedo.github.io/CVE-2025-65856/ | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| xiongmaitech xm530v200 x6-weq 8m firmware | 5.00.r02.000807d8.10010.346624.s.onvif_21.06 |
CPE
Remediation
| |
| xiongmaitech xm530v200 x6-weq 8m | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 5, 2026 | Initial Analysis | [email protected] |
| Dec 22, 2025 | CVE Modified | CISA-ADP |
| Dec 22, 2025 | New CVE Received | [email protected] |