Xiongmaitech develops a broad portfolio of embedded surveillance and network management devices, prominently including its AHB7008T-MH series and XMEye P2P cloud-server platform, which are widely deployed in security and monitoring infrastructure. Vulnerabilities affecting the vendor skew strongly toward critical severity and frequently acquire public exploit code, centered on memory-safety issues such as classic buffer overflows and improper buffer-boundary enforcement, alongside authentication and data-transmission weaknesses endemic to networked embedded systems. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xiongmaitech over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10088CRITICAL Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725. | Jun 8, 2018 | 9.8 | 72 | NO | YES |
CVE-2017-7577CRITICAL XiongMai uc-httpd has directory traversal allowing the reading of arbitrary files via a "GET ../" HTTP request. | Apr 7, 2017 | 9.8 | 47 | NO | NO |
CVE-2025-65856CRITICAL Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensiti | Dec 22, 2025 | 9.8 | 39 | NO | NO |
CVE-2017-16725CRITICAL A Stack-based Buffer Overflow issue was discovered in Xiongmai Technology IP Cameras and DVRs using the NetSurveillance Web interface. The stack-based buffer overflow vulnerability | Dec 20, 2017 | 9.8 | 35 | NO | NO |
CVE-2022-45460CRITICAL Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow an unauthenticated and remote u | Mar 28, 2023 | 9.8 | 32 | NO | NO |
CVE-2021-41506CRITICAL Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI3518_50H10L_S39 V4.02.R11.7601.Nat.Onvif.20170420, V4.02.R11.Na | Jun 30, 2022 | 9.8 | 31 | NO | NO |
CVE-2018-17915CRITICAL All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server do not encrypt all device communication. This includes the XMeye service and firmware update communicat | Oct 10, 2018 | 9.8 | 31 | NO | NO |
CVE-2020-22253CRITICAL Xiongmai Technology Co devices AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, and HI3518E_50H10L_S39 were all discovered t | Apr 6, 2022 | 9.8 | 30 | NO | NO |
CVE-2025-65857HIGH An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials | Dec 22, 2025 | 7.5 | 27 | NO | NO |
CVE-2022-45045HIGH Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow authenticated users to execute | Dec 1, 2022 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xiongmaitech.
Media articles that mention a CVE ID that affects a product developed by Xiongmaitech — matched by CVE ID, not by vendor name.