When an attacker uses a man-in-the-middle attack to sniff the request packets with success logging in through ONVIF, he can log in to the device by replaying the user's login packet.
https://www.databreachtoday.com/critical-flaws-found-in-dahua-cameras-a-29093
https://www.dahuasecurity.com/support/cybersecurity/details/1017