logo

Unpatched and Exposed: Public PoC Released for Critical 9.8 CVSS Xiongmai IP Camera Flaw

ID: cbd25ec4-279f-5736-b49a-c58166f69b0c

STIX ID: report--cbd25ec4-279f-5736-b49a-c58166f69b0c

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Ddos

...
...

**Executive Summary:** A critical unauthenticated ONVIF authentication‑bypass vulnerability (CVE-2025-65856) affecting Hangzhou Xiongmai XM530 IP cameras (specific vulnerable firmware listed) has a CVSS of 9.8, public proof-of-concept code is circulating, the vendor has not issued a patch, and thousands of devices indexed on Shodan are exposed; attackers can view live feeds, harvest credentials, control PTZ and relays, and retrieve network/device configurations, so immediate mitigations (isolate devices, use VPNs/gateways, monitor traffic and listed ports) are advised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.