PT-2026-41997 · Live555 · Live555
Vulncheck
·
Published
2026-05-19
·
Updated
2026-05-28
·
CVE-2026-41470
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
LIVE555 versions prior to 2026.04.22
Description
An authorization bypass exists in the RTSP session command handling. This allows attackers to replay valid Session tokens from unauthenticated connections. By obtaining a valid Session token, an attacker can issue 'PLAY' and 'TEARDOWN' commands from a separate TCP connection without authentication. This can lead to server crashes due to virtual function call errors or the disruption of active streams by terminating victim sessions.
Recommendations
Update to version 2026.04.22.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Live555