CVE-2025-65857
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials enabling direct unauthorized video stream access.
Affected (1)
Products: Xiongmaitech: Xm530v200 X6 Weq 8m Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.00.r02.000807d8.10010.346624.s.onvif_21.06 |
| Running on/with | Platform Versions |
|---|---|
Xiongmaitech Xm530v200 X6 Weq 8m | All versions |
References (2)
Source: cve@mitre.org
ExploitMitigationThird Party Advisory
Source: cve@mitre.org
Timeline
No history available yet.