Xiongmai IP Camera Vulnerability Let Attackers Bypass Authentication and have Remote Access
ID: 25eb9652-f22e-51e2-8cb8-295b1f4f7511
STIX ID: report--25eb9652-f22e-51e2-8cb8-295b1f4f7511
Feed Name: cybersecurityNews.com
Threat Score
A critical authentication-bypass vulnerability (CVE-2025-65856) in Hangzhou Xiongmai XM530 IP cameras' firmware (specific V5.00.R02...) allows unauthenticated attackers to access live video, control camera settings, and extract data; CISA issued an urgent alert after a researcher published a public PoC and recommends isolating cameras, removing internet exposure, using VPNs, updating software, and performing impact assessments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
