CVE-2026-51598 Details
Description
An input validation vulnerability in the RTSP service of MERCURY MIPC252W IP Camera v1.0.5 Build 230306 Rel.79931n) allows an unauthenticated, network-adjacent attacker to cause a denial of service via a crafted DESCRIBE request with a malformed URL in the request line.
A denial-of-service vulnerability has been identified in the RTSP service of the MERCURY MIPC252W IP Camera, specifically in version 1.0.5 Build 230306 Rel.79931n. The vulnerability arises from improper input validation in the RTSP DESCRIBE requests, allowing an unauthenticated, network-adjacent attacker to disrupt the camera's RTSP state machine and cause an IP-level authentication lockout. The issue occurs when the camera fails to adequately validate the URL in the DESCRIBE request line, allowing malformed URLs to bypass initial parsing and enter the authentication process. This flaw leads to two main consequences: immediate corruption of the RTSP state machine, requiring a new connection to restore normal operation, and an abnormal accumulation of authentication failure counts that can lock out the source IP from RTSP authentication for an extended period, disrupting video streaming and camera accessibility for legitimate users.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 9, 2026CISA-ADP
Assessed Jul 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/kkkk2222874/cve_ID_report/blob/main/MERCURY_MIPC252W/MERCURY_MIPC252W_6th/README.md | CISA-ADP | ExploitTechnical Analysis |
| https://github.com/kkkk2222874/cve_ID_report/blob/main/MERCURY_MIPC252W/MERCURY_MIPC252W_6th/README.md | [email protected] | ExploitTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| MERCURY MIPC252W | 1.0.5 Build 230306 Rel.79931n |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |
Volerion