PatchSiren cyber security CVE debrief
CVE-2025-11852 Apeman CVE debrief
CVE-2025-11852 is a remotely reachable authentication issue in the ONVIF service on Apeman ID71 devices. CISA’s advisory says manipulation of the /onvif/device_service endpoint can result in missing authentication, and it notes that exploit code has been made public. The advisory also states the vendor did not respond to early coordination attempts. Based on the published CVSS v3.1 vector, the issue is rated medium severity and appears to have limited confidentiality impact without reported integrity or availability impact.
- Vendor
- Apeman
- Product
- ID71
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-10
- Original CVE updated
- 2026-03-10
- Advisory published
- 2026-03-10
- Advisory updated
- 2026-03-10
Who should care
Organizations that operate Apeman ID71 cameras, especially if the ONVIF service is reachable from internal or external networks. Security and facilities teams responsible for IP cameras, building systems, or other internet-connected video devices should review exposure and access controls.
Technical summary
The advisory describes an unauthenticated remote condition affecting an unknown function in /onvif/device_service within the ONVIF service component. The reported result is missing authentication, which can permit unauthorized access to the service. CISA’s CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N (5.3), indicating network reachability with no privileges or user interaction required and limited confidentiality impact.
Defensive priority
Medium. Prioritize if the device is internet-facing, reachable from user networks, or used in environments where camera access should be tightly restricted.
Recommended defensive actions
- Identify all Apeman ID71 devices and confirm whether /onvif/device_service is reachable from untrusted networks.
- Restrict network exposure with segmentation, firewall rules, and access-control lists so ONVIF services are only reachable from approved management hosts.
- Review device and surrounding network logs for unexpected ONVIF access attempts or unauthorized use.
- If possible, apply vendor guidance or coordinate through Apeman support using the contact information provided in the CISA advisory.
- If compensating controls are needed, disable or tightly limit ONVIF functionality where operationally feasible.
- Use CISA ICS recommended practices to strengthen device isolation, credential handling, and monitoring around exposed industrial/IoT assets.
Evidence notes
This debrief is based on the CISA CSAF advisory ICSA-26-069-01 published on 2026-03-10, which names CVE-2025-11852 and describes a remote missing-authentication condition in Apeman ID71 /onvif/device_service. The advisory notes that exploit code was publicly available and that the vendor did not respond to early contact attempts. The supplied advisory metadata includes CVSS v3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N and an SSVCv2 note dated 2026-03-09 in the source context.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-11852 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-11852
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-11852 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-11852
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-069-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.