CVE-2025-65857
7.5Xiongmai · XM530 IP cameras
Xiongmai XM530 IP cameras expose RTSP URIs containing hardcoded credentials, allowing unauthenticated attackers to access video streams.
Executive summary
A critical vulnerability in Xiongmai XM530 IP cameras allows unauthenticated attackers to gain unauthorized access to live video streams due to hardcoded credentials.
Vulnerability
This is an authentication bypass vulnerability where the GetStreamUri function exposes RTSP URIs containing hardcoded credentials. It requires no authentication to trigger, allowing any network-adjacent attacker to view sensitive video feeds.
Business impact
The exploitation of this vulnerability leads to a total loss of confidentiality regarding physical surveillance data. With a CVSS score of 7.5, this high-severity flaw poses significant risks to privacy, physical security, and regulatory compliance for organizations relying on these cameras for site monitoring.
Remediation
Immediate Action: Restrict network access to the affected devices by placing them on an isolated VLAN or behind a firewall that blocks external RTSP access.
Proactive Monitoring: Monitor network traffic for unusual or unauthorized requests to the RTSP service (port 554) and review device logs for unexpected connection attempts.
Compensating Controls: Implement strict network segmentation and disable RTSP streaming if the functionality is not required for daily operations.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept repository is available on GitHub.
Analyst recommendation
Given the exposure of live video feeds, organizations must treat this vulnerability with high priority. We recommend immediate network-level isolation of all affected Xiongmai cameras while awaiting further guidance or a firmware patch from the vendor.