Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Xiongmaitech

First CVE: Apr 7, 2017Active for: 9 yearsTotal CVEs: 17
45.6
VTI Score
High

Xiongmaitech develops a broad portfolio of embedded surveillance and network management devices, prominently including its AHB7008T-MH series and XMEye P2P cloud-server platform, which are widely deployed in security and monitoring infrastructure. Vulnerabilities affecting the vendor skew strongly toward critical severity and frequently acquire public exploit code, centered on memory-safety issues such as classic buffer overflows and improper buffer-boundary enforcement, alongside authentication and data-transmission weaknesses endemic to networked embedded systems. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
8.3
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Xiongmaitech over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 7, 2017
9 years ago
Most Recent CVE
Dec 22, 2025
215 days ago

Products(455 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-10088CRITICAL
Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725.
Jun 8, 20189.872NOYES
CVE-2017-7577CRITICAL
XiongMai uc-httpd has directory traversal allowing the reading of arbitrary files via a "GET ../" HTTP request.
Apr 7, 20179.847NONO
CVE-2025-65856CRITICAL
Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensiti
Dec 22, 20259.839NONO
CVE-2017-16725CRITICAL
A Stack-based Buffer Overflow issue was discovered in Xiongmai Technology IP Cameras and DVRs using the NetSurveillance Web interface. The stack-based buffer overflow vulnerability
Dec 20, 20179.835NONO
CVE-2022-45460CRITICAL
Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow an unauthenticated and remote u
Mar 28, 20239.832NONO
CVE-2021-41506CRITICAL
Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI3518_50H10L_S39 V4.02.R11.7601.Nat.Onvif.20170420, V4.02.R11.Na
Jun 30, 20229.831NONO
CVE-2018-17915CRITICAL
All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server do not encrypt all device communication. This includes the XMeye service and firmware update communicat
Oct 10, 20189.831NONO
CVE-2020-22253CRITICAL
Xiongmai Technology Co devices AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, and HI3518E_50H10L_S39 were all discovered t
Apr 6, 20229.830NONO
CVE-2025-65857HIGH
An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials
Dec 22, 20257.527NONO
CVE-2022-45045HIGH
Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow authenticated users to execute
Dec 1, 20228.827NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
24%
29%
47%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (5.9%)
Network13 (76.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network3 (17.6%)
Attack Complexity
Low15 (88.2%)
High2 (11.8%)
Unknown0 (0.0%)
User Interaction
None17 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (11.8%)
High0 (0.0%)
None15 (88.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
5.9% of CVEs· 96th percentile
ExploitDB
1 CVE
5.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Xiongmaitech.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Xiongmaitech — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Xiongmaitech's Products

View all 2 CNAs →

Top CWEs