CVE-2025-65857: High severity Xiongmai XM530 IP cameras vulnerability
An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials enabling direct unauthorized video stream access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to ONVIF and RTSP services (e.g., block/inhibit direct access from untrusted networks at the network/firewall level) to prevent unauthorized use of exposed RTSP URIs with hardcoded credentials.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-65857?
CVE-2025-65857 is classified as a high severity vulnerability due to the exposure of hardcoded credentials that allow unauthorized access to video streams.
How do I fix CVE-2025-65857?
To fix CVE-2025-65857, update the firmware of the Xiongmai XM530 IP cameras to a version that addresses this vulnerability.
What are the potential risks associated with CVE-2025-65857?
The risks include unauthorized access to live video feeds and potential privacy violations.
Which devices are affected by CVE-2025-65857?
CVE-2025-65857 specifically affects the Xiongmai XM530 IP cameras running firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06.
Is there any workaround for CVE-2025-65857 before applying a patch?
Currently, there are no known workarounds for CVE-2025-65857, so updating the firmware is the recommended course of action.