Xiongmai IP Camera Flaw Lets Attackers Bypass Authentication
ID: d2b99ebb-7039-5136-ab57-9d8b84779b80
STIX ID: report--d2b99ebb-7039-5136-ab57-9d8b84779b80
Feed Name: GBHackers
Threat Score
A critical authentication-bypass vulnerability (CVE-2025-65856, CVSS 9.8) affecting Hangzhou Xiongmai XM530 IP Cameras’ firmware allows unauthenticated remote access to sensitive device data; a public PoC exists and CISA has issued an alert recommending immediate network isolation, firewalling, VPN enforcement for admin access, and incident reporting to CISA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
