Products: 8
    Vulnerabilities: 13
    Known Exploited: 0
    5
    Critical Level Threats
    2
    High Level Threats
    6
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-51597

    MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authentication. An adjacent network attacker can capture a legitimate authentication exchange and replay the nonce and response values in a new connection to bypass authentication without knowledge of the device credentials, gaining unauthorized access to the live video stream.

    Last Modified: Jul 25, 2026
    Published: Jul 09, 2026

    CVE-2026-51599

    An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n allows an unauthenticated remote attacker to render an individual TCP connection temporarily unusable via sending an RTSP request with a Content-Length header but no corresponding message body. The affected RTSP parser enters a body-waiting state instead of rejecting the malformed request, causing all subsequent data on the connection to be silently consumed as body content until a server-side timeout closes the connection.

    Last Modified: Aug 03, 2026
    Published: Jul 09, 2026

    CVE-2026-51598

    Denial of Service via Malformed RTSP DESCRIBE Request on MERCURY MIPC252W IP Camera

    Last Modified: Aug 01, 2026
    Published: Jul 09, 2026

    CVE-2026-31256

    A null pointer dereference vulnerability exists in the RTSP service of the MERCURY MIPC252W 1.0.5 Build 230306 Rel.79931n. During the processing of a SETUP request for the path rtsp://<IP>:554/stream1/track2, the device fails to properly validate the Transport header field. When this header is improperly constructed, the RTSP service can dereference a NULL pointer during request parsing. Successful exploitation causes the device to crash and automatically reboot.

    Last Modified: May 05, 2026
    Published: Apr 27, 2026

    CVE-2026-35902

    Denial of Service via Persistent Digest Authentication Failure in MERCURY MIPC252W RTSP Service

    Last Modified: May 05, 2026
    Published: Apr 27, 2026
    Items Per Page