PT-2026-35511 · Mercury · Mipc252W
Yankang
·
Published
2026-04-27
·
Updated
2026-05-05
·
CVE-2026-35903
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MERCURY MIPC252W version 1.0.5 Build 230306 Rel.79931n
Description
An improper authentication issue exists in the RTSP service. Following a successful Digest authentication during an initial 'DESCRIBE' request, the device fails to verify the Digest response parameter in subsequent RTSP requests within the same session. Consequently, RTSP methods including 'SETUP', 'PLAY', and 'TEARDOWN' can be processed even if the
Authorization header contains an empty or invalid response value, provided the nonce and session identifier match a previously authenticated session. This allows an attacker with network access to reuse session parameters and issue unauthorized RTSP control commands without a valid Digest response.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mipc252W