Impact
The vulnerability is an improper input validation flaw in the RTSP service of MERCURY MIPC252W IP Camera v1.0.5 Build 230306 Rel.79931n. An unauthenticated attacker on the same local network can send a crafted DESCRIBE request with a malformed URL, causing the camera to crash or reset. The result is an interruption of the live video feed and any dependent services. This vulnerability is classified as CWE-20.
Affected Systems
Only the MERCURY MIPC252W IP Camera running firmware v1.0.5 Build 230306 Rel.79931n is affected. No other models, vendors, or firmware builds are known to be vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate rating, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, so no widespread active exploits are known. Based on the description, the likely attack vector is a network‑adjacent attacker who can access the camera's RTSP port to send the malformed DESCRIBE request and trigger a denial of service.
OpenCVE Enrichment