CVE-2025-11852

MEDIUM

Apeman ID71 218.53.203.117 - Unauthenticated Improper Authentication in ONVIF Service

Title source: llm
STIX 2.1

Description

A vulnerability was found in Apeman ID71 218.53.203.117. The impacted element is an unknown function of the file /onvif/device_service of the component ONVIF Service. Performing manipulation results in missing authentication. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry
https://vuldb.com/?id.328798
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.328798
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.668899

Scores

CVSS v3 5.3
EPSS 0.0057
EPSS Percentile 42.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-287 CWE-306
Status published
Products (1)
Apeman/ID71 218.53.203.117
Published Oct 16, 2025
Tracked Since Feb 18, 2026