logo

Xiongmai IP Camera Flaw Lets Attackers Bypass Authentication

ID: d2b99ebb-7039-5136-ab57-9d8b84779b80

STIX ID: report--d2b99ebb-7039-5136-ab57-9d8b84779b80

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Divya

...
...

A critical authentication-bypass vulnerability (CVE-2025-65856, CVSS 9.8) affecting Hangzhou Xiongmai XM530 IP Cameras’ firmware allows unauthenticated remote access to sensitive device data; a public PoC exists and CISA has issued an alert recommending immediate network isolation, firewalling, VPN enforcement for admin access, and incident reporting to CISA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.