9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video streams. The ONVIF implementation fails to enforce authentication on 31 critical endpoints, enabling direct unauthorized video stream access.
AI Analysis
Authentication bypass vulnerability allowing unauthorized access to sensitive device information and live video streams
Basic Information
ID
CVE-2025-65856
Source
mitre
Published
Dec 22, 2025 at 00:00
Modified
Dec 22, 2025 at 21:22
Affected Product
Vendor
Xiongmai
Product
Xiongmai XM530 IP camera
Version
Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06
Affected Versions
n/a n/a n/a
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
Xiongmai
Product
Xiongmai XM530 IP camera
Version
Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06