CVE-2025-65856 is a missing-authentication vulnerability in the ONVIF implementation of Xiongmai XM530 IP cameras running firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. Authentication is not enforced on 31 critical ONVIF endpoints, allowing unauthenticated remote access to functions and information that should require login.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository provides proof-of-concept code for CVE-2025-65856 affecting Xiongmai XM530 IP cameras where ONVIF can be accessed without proper authentication, allowing disclosure of sensitive device information and retrieval of RTSP stream URIs. Structure: - Top-level README.md: describes the issue, impact (unauth access to device info and live streams), and a tested model/firmware. - Curl/ directory: four shell PoCs that send unauthenticated SOAP requests via curl to ONVIF endpoints on port 8899: - get_device_capabilities.sh -> POST /onvif/device_service (GetCapabilities) and save device_capabilities.xml. - get_device_information.sh -> POST /onvif/device_service (GetDeviceInformation) and save device_information.xml. - get_device_profiles.sh -> POST /onvif/media_service (GetProfiles) and save device_profiles.xml. - get_device_stream.sh -> POST /onvif/media_service (GetStreamUri) with a provided ProfileToken; saves device_stream.xml or device_stream_main.xml/device_stream_extra.xml for PROFILE_000/PROFILE_001. These scripts validate the argument as an IPv4 address and format output using xmllint. - Python/ directory: a Python PoC (xm_onvif_auth_bypass.py) using the onvif-zeep library to connect to the camera (default user 'admin', empty password unless provided), then: 1) calls devicemgmt.GetDeviceInformation() to print manufacturer/model/firmware/serial/hardware ID, 2) enumerates media profiles via media.GetProfiles(), printing configuration details, 3) requests RTSP URIs via media.GetStreamUri() for each profile and prints the returned rtsp:// URI and metadata. Packaging files (pyproject.toml, uv.lock) indicate dependency on onvif-zeep and Python >= 3.14. Overall capability: network-based unauthenticated interaction with ONVIF Device and Media services to enumerate device metadata and obtain RTSP stream URLs, which can be used to access live video streams if the camera accepts the unauthenticated ONVIF-derived URIs.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical authentication bypass vulnerability in Hangzhou Xiongmai XM530 IP camera firmware caused by a missing authentication check, allowing unauthenticated remote access to administrative functionality.
A critical authentication bypass vulnerability in Xiongmai XM530 IP cameras (Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06) allows unauthenticated remote attackers to access sensitive device information and live video streams due to missing authentication on 31 ONVIF endpoints.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.