Junglewise Threat Intelligence

CVE-2025-65857: Xiongmai XM530 IP Camera Hardcoded RTSP Credentials Exposure

CVE-2025-65857 · Severity: high · CVSS 7.5 · Published 2025-12-22

Executive brief

Xiongmai XM530 IP cameras, widely used in residential and commercial security, contain a security flaw that exposes live video feeds to unauthorized users. The cameras' internal software provides direct links to video streams that include permanent, unchangeable login credentials. An attacker can use these links to remotely monitor live video and audio without the owner's knowledge or permission.

Technical details

A hardcoded credentials vulnerability (CWE-798) exists in the ONVIF Media Service component of Xiongmai XM530 IP cameras. The 'GetStreamUri' endpoint returns RTSP URIs that embed a static username ('wphd') and password ('2MNswbQ5') in plaintext. These credentials are identical across all affected devices and do not change even if the administrator password is modified. When combined with an authentication bypass in the ONVIF service (CVE-2025-65856), a remote, unauthenticated attacker can retrieve these URIs and gain full access to live video and audio streams. No patch is currently available, and the vendor's security contact infrastructure is reportedly non-functional.

Affected products

  • Hangzhou Xiongmai Technology Co., Ltd. XM530 IP Camera Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 and likely all V5.00.R02.* versions

Timeline

  • 2025-11: other: Vulnerability discovered during security assessment
  • 2025-12-16: other: CVE-2025-65857 assigned by MITRE
  • 2025-12-17: other: Vendor contact attempted (failed due to server misconfiguration)
  • 2025-12-22: disclosed: Public disclosure of vulnerability details and PoC

References

Related threats