PT-2025-52721 · Xiongmai · Xiongmai Xm530 Ip Cameras
Luis Miranda Acebedo
·
Published
2025-12-22
·
Updated
2026-05-07
·
CVE-2025-65857
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Xiongmai XM530 IP cameras version V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06
Description
The
GetStreamUri function exposes RTSP URIs that include hardcoded credentials, allowing unauthorized access to direct video streams. The affected device is an IP camera.Recommendations
Update to a newer firmware version that addresses this issue. As a temporary workaround, restrict network access to the camera to trusted networks only.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xiongmai Xm530 Ip Cameras