CVE-2025-65856CRITICAL 9.8EPSS p53.3%

CVE-2025-65856CVE-2025-65856

Description

Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video streams. The ONVIF implementation fails to enforce authentication on 31 critical endpoints, enabling direct unauthorized video stream access.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.85% probability of exploitation · percentile 53.3% · 2026-06-19T12:03:05Z
Published2025-12-22
Last modified2026-01-05

Underlying weaknesses· 1

CWE-306

References

  1. http://hangzhou.com
  2. http://ip.com
  3. https://luismirandaacebedo.github.io/CVE-2025-65856/

1

TypeTargetConfidenceTier
WeaknessMissing Authentication for Critical Functioncwe-3060%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-30026
CVE
Dahua IP Camera Authentication Bypass Vulnerability
CVE
CVE-2026-25775
CVE
CVE-2025-64055
CVE
CVE-2026-8598
CVE
CVE-2025-13607
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.