Apeman Cameras
Three critical vulnerabilities were discovered in Apeman ID71 cameras affecting all versions, including insufficiently protected credentials, cross-site scripting, and missing authentication in the ONVIF service. The vulnerabilities have CVSS scores ranging from 3.5 to 9.8, with public exploits available, and the vendor has not responded to CISA's coordination requests. CISA recommends minimizing network exposure and implementing defensive measures such as firewalls and VPNs.
Summary
Three critical vulnerabilities were discovered in Apeman ID71 cameras affecting all versions, including insufficiently protected credentials, cross-site scripting, and missing authentication in the ONVIF service. The vulnerabilities have CVSS scores ranging from 3.5 to 9.8, with public exploits available, and the vendor has not responded to CISA's coordination requests. CISA recommends minimizing network exposure and implementing defensive measures such as firewalls and VPNs.
Indicators of Compromise
- cve — CVE-2025-11126
- cve — CVE-2025-11851
- cve — CVE-2025-11852