CVE-2025-65856Disclosure(xiongmaitech / xm530v200_x6-weq_8m)

HIGHCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch xiongmaitech xm530v200_x6-weq_8m systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video streams. The ONVIF implementation fails to enforce authentication on 31 critical endpoints, enabling direct unauthorized video stream access.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • xm530v200_x6-weq_8m
  • xm530v200_x6-weq_8m_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-24); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
xm530v200_x6-weq_8mxm530v200_x6-weq_8m_firmware

2 versions affected across 2 products

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-23: 1Mentions · 2026-04-24: 2Mentions · 2026-04-25: 1PoC Mentioned / Linked · 2026-04-24: 1Exploit Tool / Code · 2026-04-24: 1Active Exploitation · 2026-04-25: 1Patch / Workaround · 2026-04-24: 1Technical Details · 2026-04-23: 1Technical Details · 2026-04-24: 2Technical Details · 2026-04-25: 104-2304-2404-25
Signal classification3 categories
Disclosure
250.0%
PoC
125.0%
Active Exploitation
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-231
Disclosure1
2026-04-242
Disclosure1PoC1
2026-04-251
Active Exploitation1
Full discourse4 posts
  • kokumօtօ@__kokumoto
    PoC

    Xiongmai社IPカメラに重大(Critical)な脆弱性。CVE-2025-65856はCVSSスコア9.8の認証回避、というか認証の欠如。PoC(攻撃の概念実証コード)公開済み。修正版ファームウェアあり。 https://securityonline.info/public-poc-no-patch-cve-2025-65856-xiongmai-ip-camera/

    Post summary

    Xiongmai IP cameras are vulnerable to an authentication bypass (CVE‑2025‑65856, CVSS 9.8); a PoC is published and a fixed firmware update is available.

    010311.5K
    7.6K followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: CISA warns critical Xiongmai XM530 IP Camera bug CVE-2025-65856 lets attackers bypass authentication for remote access across commercial facilities. https://threatcluster.io/cluster/critical-vulnerability-in-xiongmai-ip-cameras-allows-remote--3d68f273

    Post summary

    CISA releases a critical warning about CVE-2025-65856, exposing an authentication bypass in Xiongmai XM530 IP cameras that could enable remote access across commercial facilities.

    00010622
    160 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2025-65856 in Xiongmai XM530 cameras to bypass authentication and access live video streams. This vulnerability enables lateral movement from compromised IoT devices across network segments. Runtime segmentation helps contain such post-compromise activity. #IoTSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/xiongmai-xm530-ip-camera-authentication-bypass-cve-2025-65856

    Post summary

    The report confirms that attackers are actively exploiting CVE-2025-65856 on Xiongmai XM530 cameras to bypass authentication and enable lateral movement, with no patch discussed but runtime segmentation offered as a containment measure.

    00000630
    1.9K followersView on X
  • WindowsForum@windowsforum
    Disclosure

    🚨 Auth bypass on Xiongmai XM530 IP cams (CVE-2025-65856)… so your “secure” livestream was just waiting for a stranger. This matters: security fail ≠ patch ASAP, it’s panic now. #Windows #Security https://windowsforum.com/threads/cisa-critical-flaw-in-xiongmai-xm530-ip-cameras-cve-2025-65856-auth-bypass.414909/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #CisaAdvisory #IpCameraSecurity #Cve202565856 https://t.co/1oaImWmhvn

    Post summary

    The tweet announces the discovery of an authentication bypass in Xiongmai XM530 IP cameras (CVE-2025-65856) without providing PoC, exploit code, or patch details, classifying it as a disclosure.

    00000695
    1.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWxiongmaitechxm530v200_x6-weq_8m---
OSxiongmaitechxm530v200_x6-weq_8m_firmware5.00.r02.000807d8.10010.346624.s.onvif_21.06--

Explore more