Description
An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n allows an unauthenticated remote attacker to render an individual TCP connection temporarily unusable via sending an RTSP request with a Content-Length header but no corresponding message body. The affected RTSP parser enters a body-waiting state instead of rejecting the malformed request, causing all subsequent data on the connection to be silently consumed as body content until a server-side timeout closes the connection.
Published: 2026-07-09
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An insufficient input validation flaw in the RTSP service of the MERCURY MIPC252W camera allows an unauthenticated attacker to send an RTSP request that includes a Content-Length header but no body. The RTSP parser fails to reject the malformed request and instead enters a body‑waiting state, causing all subsequent data sent over the same TCP connection to be consumed as body content. The connection thus becomes unusable until a server‑side timeout terminates the session, resulting in a temporary denial of service for the camera.

Affected Systems

The vulnerability affects MERCURY MIPC252W camera firmware v1.0.5 Build 230306 Rel.79931n, as referenced in the advisory linked at https://github.com/kkkk2222874/cve_ID_report/blob/main/MERCURY_MIPC252W/MERCURY_MIPC252W_7th/README.md.

Risk and Exploitability

The CVSS score of 9.8 indicates a high severity for denial of service, and an EPSS score of less than 1 % suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack can be launched remotely over the standard RTSP port and does not require authentication or prior compromise of the device.

Generated by OpenCVE AI on July 26, 2026 at 16:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available firmware update that addresses the RTSP parsing flaw, as recommended by the manufacturer.
  • If RTSP functionality is not required for your deployment, disable the RTSP service on the camera.
  • Configure network controls such as firewalls or ACLs to limit inbound RTSP traffic to trusted IP addresses only.

Generated by OpenCVE AI on July 26, 2026 at 16:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated RTSP Denial of Service in MERCURY MIPC252W Camera

Wed, 22 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Malformed RTSP Request on MERCURY MIPC252W

Thu, 16 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Malformed RTSP Request on MERCURY MIPC252W

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title RTSP Content-Length Header Exploit Causes Denial of Service on MERCURY MIPC252W Camera

Mon, 13 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title RTSP Content-Length Header Exploit Causes Denial of Service on MERCURY MIPC252W Camera

Sun, 12 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title RTSP Parser Misbehaves on Malformed Content‑Length Header, Causing Temporary Disconnection

Fri, 10 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title RTSP Parser Misbehaves on Malformed Content‑Length Header, Causing Temporary Disconnection
Weaknesses CWE-20

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Mercury
Mercury mipc252w
Vendors & Products Mercury
Mercury mipc252w

Thu, 09 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n allows an unauthenticated remote attacker to render an individual TCP connection temporarily unusable via sending an RTSP request with a Content-Length header but no corresponding message body. The affected RTSP parser enters a body-waiting state instead of rejecting the malformed request, causing all subsequent data on the connection to be silently consumed as body content until a server-side timeout closes the connection.
References

Subscriptions

Mercury Mipc252w
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-10T17:28:11.928Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51599

cve-icon Vulnrichment

Updated: 2026-07-10T17:25:49.548Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T16:15:17Z

Weaknesses
  • CWE-20

    Improper Input Validation