CVE-2025-65857

7.5

Xiongmai · XM530 IP cameras

Xiongmai XM530 IP cameras expose RTSP URIs containing hardcoded credentials, allowing unauthenticated attackers to access video streams.

Executive summary

A critical vulnerability in Xiongmai XM530 IP cameras allows unauthenticated attackers to gain unauthorized access to live video streams due to hardcoded credentials.

Vulnerability

This is an authentication bypass vulnerability where the GetStreamUri function exposes RTSP URIs containing hardcoded credentials. It requires no authentication to trigger, allowing any network-adjacent attacker to view sensitive video feeds.

Business impact

The exploitation of this vulnerability leads to a total loss of confidentiality regarding physical surveillance data. With a CVSS score of 7.5, this high-severity flaw poses significant risks to privacy, physical security, and regulatory compliance for organizations relying on these cameras for site monitoring.

Remediation

Immediate Action: Restrict network access to the affected devices by placing them on an isolated VLAN or behind a firewall that blocks external RTSP access.

Proactive Monitoring: Monitor network traffic for unusual or unauthorized requests to the RTSP service (port 554) and review device logs for unexpected connection attempts.

Compensating Controls: Implement strict network segmentation and disable RTSP streaming if the functionality is not required for daily operations.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept repository is available on GitHub.

Analyst recommendation

Given the exposure of live video feeds, organizations must treat this vulnerability with high priority. We recommend immediate network-level isolation of all affected Xiongmai cameras while awaiting further guidance or a firmware patch from the vendor.

More Xiongmai CVEs

Sources