Impact
The RTSP service of the MERCURY MIPC252W camera fails to reset after a failed Digest authentication attempt; repeated use of invalid authentication parameters keeps the service in a persistent failure state, preventing any subsequent legitimate client from authenticating, which results in a denial of service. This flaw is an instance of Improper Authentication (CWE-307) and can disrupt continuous video monitoring without altering the transmitted data.
Affected Systems
Only the MERCURY IP camera model MIPC252W running firmware version 1.0.5 Build 230306 is currently known to be vulnerable; no other vendors or products have reported this issue.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity. The EPSS score of <1 % suggests a low probability of immediate exploitation, and the vulnerability is not listed in CISA’s KEV catalog. An attacker does not need any prior credentials; a single unauthenticated network connection to the camera’s RTSP interface can trigger the attack, typically over TCP port 554 – this inference is based on standard RTSP deployments. Successful exploitation fully halts authentication, effectively denying legitimate clients and compromising surveillance coverage in exposed environments.
OpenCVE Enrichment