CVE-2026-51599 Details
Description
An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n allows an unauthenticated remote attacker to render an individual TCP connection temporarily unusable via sending an RTSP request with a Content-Length header but no corresponding message body. The affected RTSP parser enters a body-waiting state instead of rejecting the malformed request, causing all subsequent data on the connection to be silently consumed as body content until a server-side timeout closes the connection.
A denial-of-service vulnerability has been identified in the RTSP service of the MERCURY MIPC252W IP camera, specifically in firmware version 1.0.5 Build 230306 Rel.79931n. The vulnerability arises from inadequate input validation in the RTSP parser, which fails to properly handle requests that include a Content-Length header without a corresponding message body. This flaw allows an unauthenticated remote attacker to disrupt an individual TCP connection by sending a malformed RTSP request. Instead of rejecting the request, the parser enters a body-waiting state, causing all subsequent data on the connection to be silently consumed as body content. This behavior renders the connection temporarily unusable, until a server-side timeout closes it, while other concurrent connections and video streaming sessions remain unaffected.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 9, 2026CISA-ADP
Assessed Jul 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/kkkk2222874/cve_ID_report/blob/main/MERCURY_MIPC252W/MERCURY_MIPC252W_7th/README.md | CISA-ADP | ExploitTechnical Description |
| https://github.com/kkkk2222874/cve_ID_report/blob/main/MERCURY_MIPC252W/MERCURY_MIPC252W_7th/README.md | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| MERCURY MIPC252W | 1.0.5 Build 230306 Rel.79931n |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 10, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |
Volerion