CVE-2025-65857 Details
Description
An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials enabling direct unauthorized video stream access.
A vulnerability exists in Xiongmai XM530 IP cameras running firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The issue arises from the GetStreamUri ONVIF endpoint, which exposes RTSP URIs containing hardcoded credentials. This vulnerability allows unauthorized access to live video streams. The credentials are embedded in the RTSP URI format and transmitted in plaintext over HTTP, enabling direct access to the camera's video feed without any authentication.
Users are advised to isolate the cameras on a VLAN with no internet access, block inbound connections to the RTSP port 554, and monitor RTSP connections for unexpected sessions. Given the vendor's poor security history, replacement of the cameras is strongly recommended. The vendor should remove hardcoded credentials, implement RTSP Digest Authentication, use session tokens with expiration, generate unique credentials per device, and apply rate limiting on RTSP connections.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://luismirandaacebedo.github.io/CVE-2025-65857/ | [email protected] | ExploitMitigationThird Party Advisory |
| https://www.xiongmaitech.com/en/index.php/service/notice_info/51/4 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-359 | Exposure of Private Personal Information to an Unauthorized Actor | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| xiongmaitech xm530v200 x6-weq 8m firmware | 5.00.r02.000807d8.10010.346624.s.onvif_21.06 |
CPE
Remediation
| |
| xiongmaitech xm530v200 x6-weq 8m | All versions |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 7, 2026 | CVE Modified | [email protected] |
| Jan 5, 2026 | Initial Analysis | [email protected] |
| Dec 22, 2025 | New CVE Received | [email protected] |
| Dec 22, 2025 | CVE Modified | CISA-ADP |