Unpatched and Exposed: Public PoC Released for Critical 9.8 CVSS Xiongmai IP Camera Flaw
ID: cbd25ec4-279f-5736-b49a-c58166f69b0c
STIX ID: report--cbd25ec4-279f-5736-b49a-c58166f69b0c
Feed Name: securityonline.info
**Executive Summary:** A critical unauthenticated ONVIF authentication‑bypass vulnerability (CVE-2025-65856) affecting Hangzhou Xiongmai XM530 IP cameras (specific vulnerable firmware listed) has a CVSS of 9.8, public proof-of-concept code is circulating, the vendor has not issued a patch, and thousands of devices indexed on Shodan are exposed; attackers can view live feeds, harvest credentials, control PTZ and relays, and retrieve network/device configurations, so immediate mitigations (isolate devices, use VPNs/gateways, monitor traffic and listed ports) are advised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
