CVE-2025-65857

Source
https://cve.org/CVERecord?id=CVE-2025-65857
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-65857.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-65857
Published
2025-12-22T22:16:08.530Z
Modified
2026-03-13T03:41:22.899170Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials enabling direct unauthorized video stream access.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-65857.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "5.00.r02.000807d8.10010.346624.s.onvif_21.06"
            }
        ]
    }
]