PT-2026-35511 · Mercury · Mipc252W

Yankang

·

Published

2026-04-27

·

Updated

2026-05-05

·

CVE-2026-35903

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MERCURY MIPC252W version 1.0.5 Build 230306 Rel.79931n
Description An improper authentication issue exists in the RTSP service. Following a successful Digest authentication during an initial 'DESCRIBE' request, the device fails to verify the Digest response parameter in subsequent RTSP requests within the same session. Consequently, RTSP methods including 'SETUP', 'PLAY', and 'TEARDOWN' can be processed even if the Authorization header contains an empty or invalid response value, provided the nonce and session identifier match a previously authenticated session. This allows an attacker with network access to reuse session parameters and issue unauthorized RTSP control commands without a valid Digest response.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-35903

Affected Products

Mipc252W