Description
MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authentication. An adjacent network attacker can capture a legitimate authentication exchange and replay the nonce and response values in a new connection to bypass authentication without knowledge of the device credentials, gaining unauthorized access to the live video stream.
Published: 2026-07-09
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The MERCURY MIPC252W IP camera firmware 1.0.5 (Build 230306 Rel.79931n) fails to enforce nonce expiration for RTSP Digest authentication. This flaw (CWE‑294) allows an adjacent network attacker to capture a legitimate authentication exchange and replay the nonce and response values in a new connection to bypass authentication without knowledge of the device credentials, gaining unauthorized access to the live video stream.

Affected Systems

The only documented affected device is the MERCURY MIPC252W IP camera running firmware 1.0.5 (Build 230306 Rel.79931n). No other vendors, products, or versions are listed as impacted.

Risk and Exploitability

The vulnerability’s CVSS score of 9.1 signals critical severity, while the EPSS score of < 1 % indicates a low current exploitation likelihood. It is not cataloged in CISA’s KEV list. Exploitation requires only proximity to the camera’s local network; an attacker can capture the authentication challenge/response pair and replay it on a subsequent RTSP session, achieving persistent unauthorized viewing without any credential knowledge.

Generated by OpenCVE AI on July 25, 2026 at 20:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply an official firmware update that implements nonce expiration for RTSP Digest authentication.
  • Restrict network access to, or place the device on an isolated VLAN or VPN‑protected subnet.
  • If the camera is not required to be publicly accessible, configure firewall or ACL rules to limit inbound traffic from untrusted networks.

Generated by OpenCVE AI on July 25, 2026 at 20:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 25 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title RTSP Digest Nonce Replay Exposes Live Video on MERCURY MIPC252W Camera

Wed, 22 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title RTSP Digest Nonce Replay Exposes Live Video on MERCURY MIPC252W Camera

Fri, 17 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Replayable RTSP Digest Nonce Enables Unauthorized Live Video Access

Mon, 13 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Replayable RTSP Digest Nonce Enables Unauthorized Live Video Access

Sun, 12 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Replayable RTSP Digest Authentication Exploit in MERCURY MIPC252W IP Camera
Weaknesses CWE-665

Fri, 10 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-294
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Replayable RTSP Digest Authentication Exploit in MERCURY MIPC252W IP Camera
Weaknesses CWE-665

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Mercury
Mercury mipc252w
Vendors & Products Mercury
Mercury mipc252w

Thu, 09 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authentication. An adjacent network attacker can capture a legitimate authentication exchange and replay the nonce and response values in a new connection to bypass authentication without knowledge of the device credentials, gaining unauthorized access to the live video stream.
References

Subscriptions

Mercury Mipc252w
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-10T17:28:17.973Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51597

cve-icon Vulnrichment

Updated: 2026-07-10T17:27:23.567Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-25T20:45:02Z

Weaknesses
  • CWE-294

    Authentication Bypass by Capture-replay