Description
An input validation vulnerability in the RTSP service of MERCURY MIPC252W IP Camera v1.0.5 Build 230306 Rel.79931n) allows an unauthenticated, network-adjacent attacker to cause a denial of service via a crafted DESCRIBE request with a malformed URL in the request line.
Published: 2026-07-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper input validation flaw in the RTSP service of MERCURY MIPC252W IP Camera v1.0.5 Build 230306 Rel.79931n. An unauthenticated attacker on the same local network can send a crafted DESCRIBE request with a malformed URL, causing the camera to crash or reset. The result is an interruption of the live video feed and any dependent services. This vulnerability is classified as CWE-20.

Affected Systems

Only the MERCURY MIPC252W IP Camera running firmware v1.0.5 Build 230306 Rel.79931n is affected. No other models, vendors, or firmware builds are known to be vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate rating, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, so no widespread active exploits are known. Based on the description, the likely attack vector is a network‑adjacent attacker who can access the camera's RTSP port to send the malformed DESCRIBE request and trigger a denial of service.

Generated by OpenCVE AI on July 28, 2026 at 08:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available firmware update that patches the malformed URL parsing logic.
  • Restrict access to the RTSP port so that only authorized devices on trusted networks can reach it.
  • Disable the RTSP service or enable authentication if the service is not required.

Generated by OpenCVE AI on July 28, 2026 at 08:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via Malformed RTSP DESCRIBE Request in MERCURY MIPC252W IP Camera

Thu, 23 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Malformed RTSP DESCRIBE Request in MERCURY MIPC252W IP Camera

Wed, 15 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Input Validation Vulnerability in MERCURY MIPC252W RTSP Service Leading to Denial of Service

Tue, 14 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Input Validation Vulnerability in MERCURY MIPC252W RTSP Service Leading to Denial of Service

Mon, 13 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via Malformed RTSP DESCRIBE Request in MERCURY MIPC252W IP Camera

Sun, 12 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Malformed RTSP DESCRIBE Request in MERCURY MIPC252W IP Camera

Sat, 11 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title RTSP Denial of Service via Malformed DESCRIBE Request in MERCURY MIPC252W IP Camera

Sat, 11 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title RTSP Denial of Service via Malformed DESCRIBE Request in MERCURY MIPC252W IP Camera

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Mercury
Mercury mipc252w
Vendors & Products Mercury
Mercury mipc252w

Thu, 09 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description An input validation vulnerability in the RTSP service of MERCURY MIPC252W IP Camera v1.0.5 Build 230306 Rel.79931n) allows an unauthenticated, network-adjacent attacker to cause a denial of service via a crafted DESCRIBE request with a malformed URL in the request line.
References

Subscriptions

Mercury Mipc252w
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-09T17:40:57.516Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51598

cve-icon Vulnrichment

Updated: 2026-07-09T17:40:46.910Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:00:06Z

Weaknesses
  • CWE-20

    Improper Input Validation