ZeroHour

CVE-2026-35902

PoC
CVSS 3.1
6.2 medium
EPSS
<1%p8
Published
()
Modified
Description

The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts. By repeatedly sending RTSP requests with invalid authentication parameters, an unauthenticated attacker can cause the RTSP service to enter a persistent authentication failure state, preventing legitimate clients from authenticating and leading to a denial of service.

Vendors
mercurycom
Products
mipc252w firmware
Weakness
CWE-307
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.